← Back

CVE-2025-59546

nvd nist
Published: Sep 23, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD

Description

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, administrators and content editors can set html in module titles that could include javascript which could be used for XSS based attacks. This issue has been patched in version 10.1.0.

Affected (1)

1 product
Dotnetnuke
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 10.1.0

References (1)

Timeline

No history available yet.