vciy

CVEs we hold for Dnnsoftware

Records whose assigning authority named Dnnsoftware as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-40321DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG uploaddnnsoftware Dnn.Platform
CVE-2026-40306DNN has same HostGUID for all new installsdnnsoftware Dnn.Platform
CVE-2026-40305DNN has Force Friend Request Acceptancednnsoftware Dnn.Platform
CVE-2026-24838DotNetNuke.Core Vulnerable to Stored XSS via Module Titlednnsoftware Dnn.Platform
CVE-2026-24837DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modaldnnsoftware Dnn.Platform
CVE-2026-24836DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotesdnnsoftware Dnn.Platform
CVE-2026-24833DotNetNuke.Core Vulnerable to Stored XSS in Module Descriptiondnnsoftware Dnn.Platform
CVE-2026-24784DotNetNuke.Core has a potential XSS vulnerability in modules' header and footerdnnsoftware Dnn.Platform
CVE-2025-64095DNN Insufficient Access Control - Image Upload allows for Site Content Overwritednnsoftware Dnn.Platform
CVE-2025-64094DNN vulnerable to stored cross-site-scripting (XSS) via SVG uploaddnnsoftware Dnn.Platform
CVE-2025-62802DNN CKEditor Provider allows unauthenticated upload out-of-the-boxdnnsoftware Dnn.Platform
CVE-2025-59821DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profilednnsoftware Dnn.Platform
CVE-2025-59548DNN Vulnerable to Reflected Cross-Site Scripting (XSS) in CKEditor File Browserdnnsoftware Dnn.Platform
CVE-2025-59547DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscationdnnsoftware Dnn.Platform
CVE-2025-59546DNN Vulnerable to Stored XSS Using Backend Admin Credentialsdnnsoftware Dnn.Platform
CVE-2025-59545DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt modulednnsoftware Dnn.Platform
CVE-2025-59539DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography fielddnnsoftware Dnn.Platform
CVE-2025-59535DotNetNuke.Core allows loading of unused themes on anonymous clients through query parametersdnnsoftware Dnn.Platform
CVE-2025-52488DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user inputdnnsoftware Dnn.Platform
CVE-2025-52487DNN.PLATFORM possibly allows bypass of IP Filtersdnnsoftware Dnn.Platform
CVE-2025-52486DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjectsdnnsoftware Dnn.Platform
CVE-2025-52485DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feeddnnsoftware Dnn.Platform
CVE-2025-48378Dnn.Platform vulnerable to Stored Cross-Site Scripting (XSS) with svg files rendered inlinednnsoftware Dnn.Platform
CVE-2025-48377Dnn.Platform vulnerable to Reflected Cross-Site Scripting (XSS) in module actions in edit modednnsoftware Dnn.Platform
CVE-2025-48376Dnn.Platform's Site Import could use an external source with a crafted requestdnnsoftware Dnn.Platform
CVE-2025-32374Possible Denial of Service (DoS) in DNN.PLATFORM registrationdnnsoftware Dnn.Platform
CVE-2025-32373DNN allows a registered user to enumerate and access files they should not have access todnnsoftware Dnn.Platform
CVE-2025-32372Server-Side Request Forgery (SSRF) in DotNetNuke.Corednnsoftware Dnn.Platform
CVE-2025-32371Unexpected external content may be displayed in DNN ImageHandlerdnnsoftware Dnn.Platform
CVE-2025-32036DNN allows the possibility of bypassing Captchadnnsoftware Dnn.Platform
CVE-2025-32035DNN does not check the contents of a file when uploading filesdnnsoftware Dnn.Platform
CVE-2022-2922Relative Path Traversal in dnnsoftware/dnn.platformdnnsoftware/dnn.platform
CVE-2021-40186DNN CMS Server-Side Request Forgery (SSRF)DNNSoftware DNN Platform
CVE-2020-37103DotNetNuke 9.5 - Persistent Cross-Site ScriptingDnnsoftware DotNetNuke

34 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.