CVEs we hold for Dnnsoftware
Records whose assigning authority named Dnnsoftware as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-40321DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG uploaddnnsoftware Dnn.Platform
CVE-2026-24837DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modaldnnsoftware Dnn.Platform
CVE-2026-24836DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotesdnnsoftware Dnn.Platform
CVE-2026-24833DotNetNuke.Core Vulnerable to Stored XSS in Module Descriptiondnnsoftware Dnn.Platform
CVE-2026-24784DotNetNuke.Core has a potential XSS vulnerability in modules' header and footerdnnsoftware Dnn.Platform
CVE-2025-64095DNN Insufficient Access Control - Image Upload allows for Site Content Overwritednnsoftware Dnn.Platform
CVE-2025-64094DNN vulnerable to stored cross-site-scripting (XSS) via SVG uploaddnnsoftware Dnn.Platform
CVE-2025-62802DNN CKEditor Provider allows unauthenticated upload out-of-the-boxdnnsoftware Dnn.Platform
CVE-2025-59821DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profilednnsoftware Dnn.Platform
CVE-2025-59548DNN Vulnerable to Reflected Cross-Site Scripting (XSS) in CKEditor File Browserdnnsoftware Dnn.Platform
CVE-2025-59547DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscationdnnsoftware Dnn.Platform
CVE-2025-59545DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt modulednnsoftware Dnn.Platform
CVE-2025-59539DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography fielddnnsoftware Dnn.Platform
CVE-2025-59535DotNetNuke.Core allows loading of unused themes on anonymous clients through query parametersdnnsoftware Dnn.Platform
CVE-2025-52488DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user inputdnnsoftware Dnn.Platform
CVE-2025-52486DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjectsdnnsoftware Dnn.Platform
CVE-2025-52485DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feeddnnsoftware Dnn.Platform
CVE-2025-48378Dnn.Platform vulnerable to Stored Cross-Site Scripting (XSS) with svg files rendered inlinednnsoftware Dnn.Platform
CVE-2025-48377Dnn.Platform vulnerable to Reflected Cross-Site Scripting (XSS) in module actions in edit modednnsoftware Dnn.Platform
CVE-2025-48376Dnn.Platform's Site Import could use an external source with a crafted requestdnnsoftware Dnn.Platform
CVE-2025-32373DNN allows a registered user to enumerate and access files they should not have access todnnsoftware Dnn.Platform
CVE-2025-32371Unexpected external content may be displayed in DNN ImageHandlerdnnsoftware Dnn.Platform
CVE-2025-32035DNN does not check the contents of a file when uploading filesdnnsoftware Dnn.Platform
34 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.