Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Dnn.Platform — Vulnerabilities & Security Advisories 31

All 31 CVE vulnerabilities found in Dnn.Platform, with AI-generated Chinese analysis, references, and POCs.

This page details vulnerability aggregation data for Dnn.Platform, a widely used web content management system developed by DNN Corporation, focusing on common weakness enumeration tags such as cross-site scripting and SQL injection. The collected entries encompass a comprehensive range of security flaws identified in the platform, including authentication bypasses, remote code execution risks, and insecure direct object references. The time range covered spans from the initial public disclosures in the early 2000s through recent patches issued in 2023, reflecting the long operational history of the software. Readers can utilize this resource to track a vendor's advisories by reviewing chronological bulletin releases and understanding a specific weakness class by analyzing how similar vulnerabilities manifest across different versions of the product. Additionally, users can look up a product's vulnerability history to identify patterns in security degradation or improvement over time, which aids in risk assessment and migration planning. This structured overview allows security professionals, developers, and system administrators to quickly grasp the security posture of Dnn.Platform without sifting through unstructured news articles. By consolidating these data points, the page serves as a centralized reference for evaluating past security incidents and anticipating potential future exposures in legacy or maintained instances of the platform.

Vendor: dnnsoftware

CVE IDTitleCVSSSeverityPublished
CVE-2026-40321 DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload CWE-87 8.1 High2026-04-17
CVE-2026-40306 DNN has same HostGUID for all new installs CWE-330 5.4AIMediumAI2026-04-17
CVE-2026-40305 DNN has Force Friend Request Acceptance CWE-285 4.3 Medium2026-04-17
CVE-2026-24838 DotNetNuke.Core Vulnerable to Stored XSS via Module Title CWE-79 9.1 Critical2026-01-27
CVE-2026-24837 DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal CWE-79 7.7 High2026-01-27
CVE-2026-24836 DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes CWE-79 7.7 High2026-01-27
CVE-2026-24833 DotNetNuke.Core Vulnerable to Stored XSS in Module Description CWE-79 7.7 High2026-01-27
CVE-2026-24784 DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer CWE-79 6.8 Medium2026-01-27
CVE-2025-64095 DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite CWE-434 10.0 Critical2025-10-28
CVE-2025-64094 DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload CWE-79 6.4 Medium2025-10-28
CVE-2025-62802 DNN CKEditor Provider allows unauthenticated upload out-of-the-box CWE-1188 4.3 Medium2025-10-28
CVE-2025-59548 DNN Vulnerable to Reflected Cross-Site Scripting (XSS) in CKEditor File Browser CWE-79 6.1AIMediumAI2025-09-23
CVE-2025-59547 DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscation CWE-176 5.3 Medium2025-09-23
CVE-2025-59821 DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile CWE-79 6.5 Medium2025-09-23
CVE-2025-59546 DNN Vulnerable to Stored XSS Using Backend Admin Credentials CWE-79 2.4 Low2025-09-23
CVE-2025-59545 DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module CWE-79 9.1 Critical2025-09-23
CVE-2025-59539 DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field CWE-79 6.3 Medium2025-09-23
CVE-2025-59535 DotNetNuke.Core allows loading of unused themes on anonymous clients through query parameters CWE-20 6.5 Medium2025-09-22
CVE-2025-52488 DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input CWE-200 8.6 High2025-06-21
CVE-2025-52487 DNN.PLATFORM possibly allows bypass of IP Filters CWE-863 8.2AIHighAI2025-06-21
CVE-2025-52486 DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjects CWE-79 4.3AIMediumAI2025-06-21
CVE-2025-52485 DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed CWE-79 4.6AIMediumAI2025-06-21
CVE-2025-48377 Dnn.Platform vulnerable to Reflected Cross-Site Scripting (XSS) in module actions in edit mode CWE-79 6.1AIMediumAI2025-05-23
CVE-2025-48378 Dnn.Platform vulnerable to Stored Cross-Site Scripting (XSS) with svg files rendered inline CWE-79 5.4AIMediumAI2025-05-23
CVE-2025-48376 Dnn.Platform's Site Import could use an external source with a crafted request CWE-841 3.5 Low2025-05-23
CVE-2025-32374 Possible Denial of Service (DoS) in DNN.PLATFORM registration CWE-770 5.9 Medium2025-04-09
CVE-2025-32373 DNN allows a registered user to enumerate and access files they should not have access to CWE-639 6.5 Medium2025-04-09
CVE-2025-32372 Server-Side Request Forgery (SSRF) in DotNetNuke.Core CWE-918 6.5 Medium2025-04-09
CVE-2025-32371 Unexpected external content may be displayed in DNN ImageHandler CWE-451 4.3 Medium2025-04-09
CVE-2025-32036 DNN allows the possibility of bypassing Captcha CWE-804 4.2 Medium2025-04-08

All 31 known CVE vulnerabilities affecting Dnn.Platform with full Chinese analysis, references, and POCs where available.