VendorsDNN Softwaredotnetnukeany version
Vulnerabilities

DNN Software DotNetNuke any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

61CVEs
CVE-2021-31858
DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.
Published 2022-07-20 · Modified
5.4EPSS 0.006
CVE-2022-47053
An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file.
Published 2023-04-12 · Modified
5.4EPSS 0.004
CVE-2025-52485
DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed
Published 2025-06-21 · Analyzed
5.4EPSS 0.002
CVE-2025-59547
DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscation
Published 2025-09-23 · Analyzed
5.3EPSS 0.003
CVE-2008-6540
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys.
Published 2009-03-30 · Modified
5.11 PoCEPSS 0.025
CVE-2022-2922
Relative Path Traversal in dnnsoftware/dnn.platform
Published 2022-09-30 · Modified
4.9EPSS 0.011
CVE-2025-59546
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
Published 2025-09-23 · Analyzed
4.8EPSS 0.002
CVE-2008-6542
Unspecified vulnerability in the Skin Manager in DotNetNuke before 4.8.2 allows remote authenticated administrators to perform "server-side execution of application logic" by uploading a static file that is converted into a dynamic script via unknown vectors related to HTM or HTML files.
Published 2009-03-30 · Modified
4.6EPSS 0.016
CVE-2013-4649
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the __dnnVariable parameter to the default URI.
Published 2014-03-12 · Modified
4.3EPSS 0.025
CVE-2015-1566
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2015-02-09 · Modified
4.3EPSS 0.018
CVE-2008-6644
Cross-site scripting (XSS) vulnerability in Default.aspx in DotNetNuke 4.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
Published 2009-04-07 · Modified
4.31 PoCEPSS 0.015
CVE-2005-0040
Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.
Published 2005-05-19 · Modified
4.3EPSS 0.013
CVE-2013-7335
Open redirect vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Published 2014-03-12 · Modified
4.3EPSS 0.012
CVE-2008-6732
Cross-site scripting (XSS) vulnerability in the Language skin object in DotNetNuke before 4.8.4 allows remote attackers to inject arbitrary web script or HTML via "newly generated paths."
Published 2009-04-21 · Modified
4.3EPSS 0.011
CVE-2009-1366
Cross-site scripting (XSS) vulnerability in Website\admin\Sales\paypalipn.aspx in DotNetNuke (DNN) before 4.9.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "name/value pairs" and "paypal IPN functionality."
Published 2009-04-22 · Modified
4.3EPSS 0.010
CVE-2012-1036
Cross-site scripting (XSS) vulnerability in the telerik HTML editor in DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a message.
Published 2012-04-11 · Modified
4.3EPSS 0.009
CVE-2026-40305
DNN has Force Friend Request Acceptance
Published 2026-04-17 · Analyzed
4.3EPSS 0.003
CVE-2025-32371
Unexpected external content may be displayed in DNN ImageHandler
Published 2025-04-09 · Analyzed
4.3EPSS 0.003
CVE-2025-62802
DNN CKEditor Provider allows unauthenticated upload out-of-the-box
Published 2025-10-28 · Analyzed
4.3EPSS 0.002
CVE-2013-3943
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Display Name field in the Manage Profile.
Published 2014-03-12 · Modified
3.5EPSS 0.009
CVE-2025-48376
Dnn.Platform's Site Import could use an external source with a crafted request
Published 2025-05-23 · Analyzed
3.5EPSS 0.002
← Prev2 / 2