Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Dnn.Platform — Vulnerabilities & Security Advisories 31

All 31 CVE vulnerabilities found in Dnn.Platform, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive vulnerability aggregation view for Dnn.Platform, focusing on security weaknesses associated with the DNN Corp content management system. The collected data encompasses a wide spectrum of security flaws, including cross-site scripting, SQL injection, and path traversal vulnerabilities, covering reports from early 2010 through the present day. This historical range allows for a longitudinal analysis of how the platform has evolved in response to emerging threats and how legacy code structures continue to influence modern security postures. Visitors can use this resource to track vendor advisory timelines, understanding the cadence and nature of security updates released by DNN Corp. It serves as a centralized hub for researchers and administrators to understand the broader context of specific weakness classes within the DNN ecosystem, rather than viewing them in isolation. By examining the aggregated data, users can look up a product's vulnerability history to identify patterns in recurring issues, assess the impact of past patches, and gauge the overall maturity of the product's security practices over time. This approach facilitates a deeper comprehension of the technical debt and architectural challenges inherent in long-standing web platforms. The information presented is derived from publicly available advisories and verified security reports, ensuring accuracy and relevance for security professionals conducting risk assessments or penetration testing evaluations for organizations utilizing Dnn.Platform deployments.

Vendor: dnnsoftware

CVE IDTitleCVSSSeverityPublished
CVE-2026-40321 DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload CWE-87 8.1 High2026-04-17
CVE-2026-40306 DNN has same HostGUID for all new installs CWE-330 5.4AIMediumAI2026-04-17
CVE-2026-40305 DNN has Force Friend Request Acceptance CWE-285 4.3 Medium2026-04-17
CVE-2026-24838 DotNetNuke.Core Vulnerable to Stored XSS via Module Title CWE-79 9.1 Critical2026-01-27
CVE-2026-24837 DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal CWE-79 7.7 High2026-01-27
CVE-2026-24836 DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes CWE-79 7.7 High2026-01-27
CVE-2026-24833 DotNetNuke.Core Vulnerable to Stored XSS in Module Description CWE-79 7.7 High2026-01-27
CVE-2026-24784 DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer CWE-79 6.8 Medium2026-01-27
CVE-2025-64095 DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite CWE-434 10.0 Critical2025-10-28
CVE-2025-64094 DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload CWE-79 6.4 Medium2025-10-28
CVE-2025-62802 DNN CKEditor Provider allows unauthenticated upload out-of-the-box CWE-1188 4.3 Medium2025-10-28
CVE-2025-59548 DNN Vulnerable to Reflected Cross-Site Scripting (XSS) in CKEditor File Browser CWE-79 6.1AIMediumAI2025-09-23
CVE-2025-59547 DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscation CWE-176 5.3 Medium2025-09-23
CVE-2025-59821 DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile CWE-79 6.5 Medium2025-09-23
CVE-2025-59546 DNN Vulnerable to Stored XSS Using Backend Admin Credentials CWE-79 2.4 Low2025-09-23
CVE-2025-59545 DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module CWE-79 9.1 Critical2025-09-23
CVE-2025-59539 DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field CWE-79 6.3 Medium2025-09-23
CVE-2025-59535 DotNetNuke.Core allows loading of unused themes on anonymous clients through query parameters CWE-20 6.5 Medium2025-09-22
CVE-2025-52488 DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input CWE-200 8.6 High2025-06-21
CVE-2025-52487 DNN.PLATFORM possibly allows bypass of IP Filters CWE-863 8.2AIHighAI2025-06-21
CVE-2025-52486 DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjects CWE-79 4.3AIMediumAI2025-06-21
CVE-2025-52485 DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed CWE-79 4.6AIMediumAI2025-06-21
CVE-2025-48377 Dnn.Platform vulnerable to Reflected Cross-Site Scripting (XSS) in module actions in edit mode CWE-79 6.1AIMediumAI2025-05-23
CVE-2025-48378 Dnn.Platform vulnerable to Stored Cross-Site Scripting (XSS) with svg files rendered inline CWE-79 5.4AIMediumAI2025-05-23
CVE-2025-48376 Dnn.Platform's Site Import could use an external source with a crafted request CWE-841 3.5 Low2025-05-23
CVE-2025-32374 Possible Denial of Service (DoS) in DNN.PLATFORM registration CWE-770 5.9 Medium2025-04-09
CVE-2025-32373 DNN allows a registered user to enumerate and access files they should not have access to CWE-639 6.5 Medium2025-04-09
CVE-2025-32372 Server-Side Request Forgery (SSRF) in DotNetNuke.Core CWE-918 6.5 Medium2025-04-09
CVE-2025-32371 Unexpected external content may be displayed in DNN ImageHandler CWE-451 4.3 Medium2025-04-09
CVE-2025-32036 DNN allows the possibility of bypassing Captcha CWE-804 4.2 Medium2025-04-08

All 31 known CVE vulnerabilities affecting Dnn.Platform with full Chinese analysis, references, and POCs where available.