← Back

CVE-2026-24836

nvd nist
Published: Jan 28, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Versions 9.13.10 and 10.2.0 contain a fix for the issue.

Affected (2)

1 product
Dotnetnuke
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Dnnsoftware
From 10.0.0 to 10.2.0
From 9.0.0 to 9.13.10

References (1)

Timeline

No history available yet.