Dnnsoftware
Dnnsoftware Dotnetnuke: vulnerabilidades y CVE
Dnnsoftware Dotnetnuke tiene 76 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 3 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE76
Últimos 12 meses12
Críticas3
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-15811 | Alta (7.5) | 76% | ⚠ Explotación activa | 3 jul 2019 | DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. |
| CVE-2018-18325 | Alta (7.5) | 74% | ⚠ Explotación activa | 3 jul 2019 | DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811. |
| CVE-2017-9822 | Alta (8.8) | 95% | ⚠ Explotación activa | 20 jul 2017 | DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites." |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-40321 | Alta (8) | 0.36% | — | 17 abr 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can… |
| CVE-2026-40306 | Media (6.9) | 0.29% | — | 17 abr 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from… |
| CVE-2026-40305 | Media (4.3) | 0.30% | — | 17 abr 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request… |
| CVE-2020-37103 | Media (5.1) | 0.31% | — | 3 feb 2026 | DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML files with executable scripts through journal tools. Attackers can upload XML files with XHTML… |
| CVE-2026-24838 | Media (5.4) | 0.22% | — | 28 ene 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, module title supports richtext which could include scripts that would… |
| CVE-2026-24837 | Media (5.4) | 0.28% | — | 28 ene 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, a module friendly name could include… |
| CVE-2026-24836 | Media (5.4) | 0.26% | — | 28 ene 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, extensions could write richtext in log… |
| CVE-2026-24833 | Media (5.4) | 0.21% | — | 28 ene 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, a module could install with richtext in its description field which… |
| CVE-2026-24784 | Media (4.8) | 0.19% | — | 28 ene 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, a content editor could inject scripts in… |
| CVE-2025-64095 | Crítica (9.8) | 47% | — | 28 oct 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can… |
| CVE-2025-64094 | Media (5.4) | 0.19% | — | 28 oct 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, sanitization of the content of uploaded SVG files was not covering all possible XSS… |
| CVE-2025-62802 | Media (4.3) | 0.23% | — | 28 oct 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the out-of-box experience for HTML editing allows unauthenticated users to upload files.… |
| CVE-2025-59821 | Media (6.1) | 0.21% | — | 23 sept 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, DNN’s URL/path handling and template rendering can allow specially crafted input to… |
| CVE-2025-59548 | Media (5.9) | 0.19% | — | 23 sept 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, specially crafted URLs to the FileBrowser are vulnerable to javascript injection,… |
| CVE-2025-59547 | Media (5.3) | 0.26% | — | 23 sept 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the CKEditor file upload endpoint has insufficient sanitization for filenames… |
| CVE-2025-59546 | Media (4.8) | 0.18% | — | 23 sept 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, administrators and content editors can set html in module titles that could include… |
| CVE-2025-59545 | Crítica (9) | 0.49% | — | 23 sept 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of commands that can return raw HTML. Malicious… |
| CVE-2025-59539 | Media (5.4) | 0.18% | — | 23 sept 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, when embedding information in the Biography field, even if that field is not… |
| CVE-2025-59535 | Media (6.5) | 0.43% | — | 22 sept 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary themes can be loaded through query parameters. If an installed theme had a… |
| CVE-2025-52488 | Alta (8.6) | 36% | — | 21 jun 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction… |
| CVE-2025-52487 | Alta (8.8) | 0.35% | — | 21 jun 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request or proxy to be created… |
| CVE-2025-52486 | Media (6.1) | 0.23% | — | 21 jun 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows specially crafted content in URLs to be used with… |
| CVE-2025-52485 | Media (5.1) | 0.21% | — | 21 jun 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request to inject scripts in the… |
| CVE-2025-48378 | Media (6.1) | 0.28% | — | 23 may 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could… |
| CVE-2025-48377 | Media (6) | 0.23% | — | 23 may 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a specially crafted URL may be constructed which can inject an XSS payload that is… |
| CVE-2025-48376 | Baja (2.4) | 0.24% | — | 23 may 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft a request to use an external url for a site… |
| CVE-2025-32374 | Alta (7.5) | 0.39% | — | 9 abr 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Possible denial of service with specially crafted information in the public registration form. This… |
| CVE-2025-32373 | Media (6.5) | 0.38% | — | 9 abr 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered users may be able to craft a request to enumerate/access some portal… |
| CVE-2025-32372 | Alta (7.5) | 0.38% | — | 9 abr 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated… |
| CVE-2025-32371 | Media (4.3) | 0.29% | — | 9 abr 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A url could be crafted to the DNN ImageHandler to render text from a querystring parameter. This text would… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.