← Back

Dnnsoftware

dnnsoftware

76 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Dotnetnuke
dotnetnuke

CVEs (76)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dnnsoftware
1Dotnetnuke
Jun 17, 2026
Sep 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with a...Show more
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.Show less
1Dnnsoftware
1Dotnetnuke
Nov 21, 2024
Jul 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.
1Dnnsoftware
1Dotnetnuke
Nov 7, 2025
Jul 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
1Dnnsoftware
1Dotnetnuke
Nov 21, 2024
Jul 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
1Dnnsoftware
1Dotnetnuke
Nov 7, 2025
Jul 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
1Dnnsoftware
1Dotnetnuke
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
1Dnnsoftware
1Dotnetnuke
Nov 21, 2024
Jul 3, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.
1Dnnsoftware
1Dotnetnuke
Apr 21, 2026
Jul 20, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
2Dnnsoftware
Dotnetnuke
2Dotnetnuke
Dotnetnuke
May 13, 2026
Feb 6, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
2Dnnsoftware
Dotnetnuke
2Dotnetnuke
Dotnetnuke
May 6, 2026
Aug 31, 2016
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in...Show more
Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.Show less
2Dnnsoftware
Dotnetnuke
2Dotnetnuke
Dotnetnuke
May 6, 2026
Feb 9, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
2Dnnsoftware
Dotnetnuke
2Dotnetnuke
Dotnetnuke
May 6, 2026
Mar 12, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Open redirect vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
2Dnnsoftware
Dotnetnuke
2Dotnetnuke
Dotnetnuke
May 6, 2026
Mar 12, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the __dnnVariable parameter to the default URI.
2Dnnsoftware
Dotnetnuke
2Dotnetnuke
Dotnetnuke
May 6, 2026
Mar 12, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Display Name field in the...Show more
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Display Name field in the Manage Profile.Show less
2Dnnsoftware
Dotnetnuke
2Dotnetnuke
Dotnetnuke
Apr 29, 2026
Apr 11, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the telerik HTML editor in DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a message.
2Dnnsoftware
Dotnetnuke
2Dotnetnuke
Dotnetnuke
Apr 29, 2026
Apr 11, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in DotNetNuke 6.x through 6.0.2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted URL containing text that is used within a modal popup.
2Dnnsoftware
Dotnetnuke
2Dotnetnuke
Dotnetnuke
Apr 29, 2026
Dec 9, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. NOTE: some of these...Show more
Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. NOTE: some of these details are obtained from third party information.Show less
2Dnnsoftware
Dotnetnuke
2Dotnetnuke
Dotnetnuke
Apr 24, 2026
Nov 29, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not properly filtered before d...Show more
Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not properly filtered before display in a custom results page.Show less
2Dnnsoftware
Dotnetnuke
2Dotnetnuke
Dotnetnuke
Apr 24, 2026
Nov 29, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to access version inform...Show more
The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to access version information and possibly other sensitive information.Show less
2Dnnsoftware
Dotnetnuke
2Dotnetnuke
Dotnetnuke
Apr 24, 2026
Aug 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality, via unknown vectors related to parameter validation.