dnnsoftware CVE Vulnerabilities & Metrics

Focus on dnnsoftware vulnerabilities and metrics.

Last updated: 25 Nov 2025, 23:25 UTC

About dnnsoftware Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with dnnsoftware. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total dnnsoftware CVEs: 39
Earliest CVE date: 20 Jul 2017, 12:29 UTC
Latest CVE date: 28 Oct 2025, 22:15 UTC

Latest CVE reference: CVE-2025-64095

Rolling Stats

30-day Count (Rolling): 3
365-day Count (Rolling): 23

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical dnnsoftware CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.62

Max CVSS: 6.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 27
4.0-6.9 12
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS dnnsoftware CVEs

These are the five CVEs with the highest CVSS scores for dnnsoftware, sorted by severity first and recency.

All CVEs for dnnsoftware

CVE-2025-64095 dnnsoftware vulnerability CVSS: 0 28 Oct 2025, 22:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files allowing defacing a website and combined with other issue, injection XSS payloads. This vulnerability is fixed in 10.1.1.

CVE-2025-64094 dnnsoftware vulnerability CVSS: 0 28 Oct 2025, 22:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, sanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. This vulnerability exists because of an incomplete fix for CVE-2025-48378. This vulnerability is fixed in 10.1.1.

CVE-2025-62802 dnnsoftware vulnerability CVSS: 0 28 Oct 2025, 22:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the out-of-box experience for HTML editing allows unauthenticated users to upload files. This opens a potential vector to other security issues and is not needed on most implementations. This vulnerability is fixed in 10.1.1.

CVE-2025-59821 dnnsoftware vulnerability CVSS: 0 23 Sep 2025, 18:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, DNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that is returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. This issue has been patched in version 10.1.0.

CVE-2025-59548 dnnsoftware vulnerability CVSS: 0 23 Sep 2025, 18:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, specially crafted URLs to the FileBrowser are vulnerable to javascript injection, affecting any unsuspecting user clicking such link. This issue has been patched in version 10.1.0.

CVE-2025-59547 dnnsoftware vulnerability CVSS: 0 23 Sep 2025, 18:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the CKEditor file upload endpoint has insufficient sanitization for filenames allowing probing network endpoints. A specially crafted request can be made to upload a file with Unicode characters, which would be translated into a path that could expose resources in the internal network of the hosted site. This issue has been patched in version 10.1.0.

CVE-2025-59546 dnnsoftware vulnerability CVSS: 0 23 Sep 2025, 18:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, administrators and content editors can set html in module titles that could include javascript which could be used for XSS based attacks. This issue has been patched in version 10.1.0.

CVE-2025-59545 dnnsoftware vulnerability CVSS: 0 23 Sep 2025, 18:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). This issue has been patched in version 10.1.0.

CVE-2025-59539 dnnsoftware vulnerability CVSS: 0 23 Sep 2025, 18:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, when embedding information in the Biography field, even if that field is not rich-text, users could inject javascript code that would run in the context of the website and to any other user that can view the profile including administrators and/or superusers. This issue has been patched in version 10.1.0.

CVE-2025-59535 dnnsoftware vulnerability CVSS: 0 22 Sep 2025, 21:16 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. This issue has been patched in version 10.1.0.

CVE-2025-52488 dnnsoftware vulnerability CVSS: 0 21 Jun 2025, 03:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version 10.0.1.

CVE-2025-52487 dnnsoftware vulnerability CVSS: 0 21 Jun 2025, 03:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request or proxy to be created that could bypass the design of DNN Login IP Filters allowing login attempts from IP Addresses not in the allow list. This issue has been patched in version 10.0.1.

CVE-2025-52486 dnnsoftware vulnerability CVSS: 0 21 Jun 2025, 03:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows specially crafted content in URLs to be used with TokenReplace and not be properly sanitized by some SkinObjects. This issue has been patched in version 10.0.1.

CVE-2025-52485 dnnsoftware vulnerability CVSS: 0 21 Jun 2025, 03:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request to inject scripts in the Activity Feed Attachments endpoint which will then render in the feed. This issue has been patched in version 10.0.1.

CVE-2025-48378 dnnsoftware vulnerability CVSS: 0 23 May 2025, 16:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Version 9.13.9 fixes the issue.

CVE-2025-48377 dnnsoftware vulnerability CVSS: 0 23 May 2025, 16:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Version 9.13.9 fixes the issue.

CVE-2025-48376 dnnsoftware vulnerability CVSS: 0 23 May 2025, 16:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft a request to use an external url for a site export to then be imported. Version 9.13.9 fixes the issue.

CVE-2025-32374 dnnsoftware vulnerability CVSS: 0 09 Apr 2025, 16:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Possible denial of service with specially crafted information in the public registration form. This vulnerability is fixed in 9.13.8.

CVE-2025-32373 dnnsoftware vulnerability CVSS: 0 09 Apr 2025, 16:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered users may be able to craft a request to enumerate/access some portal files they should not have access to. This vulnerability is fixed in 9.13.8.

CVE-2025-32372 dnnsoftware vulnerability CVSS: 0 09 Apr 2025, 16:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. This vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. This vulnerability is fixed in 9.13.8.

CVE-2025-32371 dnnsoftware vulnerability CVSS: 0 09 Apr 2025, 16:15 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A url could be crafted to the DNN ImageHandler to render text from a querystring parameter. This text would display in the resulting image and a user that trusts the domain might think that the information is legitimate. This vulnerability is fixed in 9.13.4.

CVE-2025-32036 dnnsoftware vulnerability CVSS: 0 08 Apr 2025, 18:16 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. The algorithm used to generate the captcha image shows the least complexity of the desired image. For this reason, the created image can be easily read by OCR tools, and the intruder can send automatic requests by building a robot and using this tool. This vulnerability is fixed in 9.13.8.

CVE-2025-32035 dnnsoftware vulnerability CVSS: 0 08 Apr 2025, 18:16 UTC

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's possible to e.g. upload an executable file renamed to be a .jpg. This file could then be executed by another security vulnerability. This vulnerability is fixed in 9.13.2.

CVE-2022-47053 dnnsoftware vulnerability CVSS: 0 12 Apr 2023, 13:15 UTC

An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file.

CVE-2022-2922 dnnsoftware vulnerability CVSS: 0 30 Sep 2022, 07:15 UTC

Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.

CVE-2021-31858 dnnsoftware vulnerability CVSS: 0 20 Jul 2022, 13:15 UTC

DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.

CVE-2021-40186 dnnsoftware vulnerability CVSS: 5.0 02 Jun 2022, 14:15 UTC

The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of possible attacks. In the most common scenario, the attacker exploits SSRF vulnerabilities to attack systems behind the firewall and access sensitive information from Cloud Provider metadata services.

CVE-2020-11585 dnnsoftware vulnerability CVSS: 4.0 06 Apr 2020, 21:15 UTC

There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file attached, e.g., by using an arbitrary small integer value in the fileIds parameter.

CVE-2020-5188 dnnsoftware vulnerability CVSS: 4.0 24 Feb 2020, 15:15 UTC

DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.

CVE-2020-5187 dnnsoftware vulnerability CVSS: 6.5 24 Feb 2020, 15:15 UTC

DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).

CVE-2020-5186 dnnsoftware vulnerability CVSS: 3.5 24 Feb 2020, 15:15 UTC

DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).

CVE-2019-12562 dnnsoftware vulnerability CVSS: 4.3 26 Sep 2019, 20:15 UTC

Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.

CVE-2018-18326 dnnsoftware vulnerability CVSS: 5.0 03 Jul 2019, 17:15 UTC

DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.

CVE-2018-18325 dnnsoftware vulnerability CVSS: 5.0 03 Jul 2019, 17:15 UTC

DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.

CVE-2018-15812 dnnsoftware vulnerability CVSS: 5.0 03 Jul 2019, 17:15 UTC

DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.

CVE-2018-15811 dnnsoftware vulnerability CVSS: 5.0 03 Jul 2019, 17:15 UTC

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

CVE-2018-14486 dnnsoftware vulnerability CVSS: 4.3 21 Mar 2019, 16:00 UTC

DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.

CVE-2017-0929 dnnsoftware vulnerability CVSS: 5.0 03 Jul 2018, 21:29 UTC

DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.

CVE-2017-9822 dnnsoftware vulnerability CVSS: 6.5 20 Jul 2017, 12:29 UTC

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."