CVE-2025-52487
- EPSS 0.29%
- Veröffentlicht 21.06.2025 02:44:58
- Zuletzt bearbeitet 15.09.2025 15:30:48
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request or proxy to be created that could bypass the design of D...
CVE-2025-52486
- EPSS 0.2%
- Veröffentlicht 21.06.2025 02:42:47
- Zuletzt bearbeitet 15.09.2025 15:40:46
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows specially crafted content in URLs to be used with TokenReplace and not be properly s...
CVE-2025-52485
- EPSS 0.18%
- Veröffentlicht 21.06.2025 02:40:38
- Zuletzt bearbeitet 15.09.2025 15:41:56
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request to inject scripts in the Activity Feed Attachments endpo...
CVE-2025-48377
- EPSS 0.2%
- Veröffentlicht 23.05.2025 15:39:40
- Zuletzt bearbeitet 26.08.2025 14:21:33
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module a...
CVE-2025-48378
- EPSS 0.24%
- Veröffentlicht 23.05.2025 15:39:03
- Zuletzt bearbeitet 26.08.2025 14:20:12
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Versi...
CVE-2025-48376
- EPSS 0.21%
- Veröffentlicht 23.05.2025 15:37:03
- Zuletzt bearbeitet 26.08.2025 14:25:37
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft a request to use an external url for a site export to then be imported. Ve...
CVE-2025-32374
- EPSS 0.32%
- Veröffentlicht 09.04.2025 15:14:51
- Zuletzt bearbeitet 26.08.2025 00:43:35
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Possible denial of service with specially crafted information in the public registration form. This vulnerability is fixed in 9.13.8.
CVE-2025-32373
- EPSS 0.31%
- Veröffentlicht 09.04.2025 15:14:43
- Zuletzt bearbeitet 26.08.2025 00:44:18
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered users may be able to craft a request to enumerate/access some portal files they should not have access...
CVE-2025-32372
- EPSS 0.32%
- Veröffentlicht 09.04.2025 15:14:35
- Zuletzt bearbeitet 26.08.2025 00:46:34
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary G...
CVE-2025-32371
- EPSS 0.25%
- Veröffentlicht 09.04.2025 15:14:29
- Zuletzt bearbeitet 26.08.2025 00:48:09
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A url could be crafted to the DNN ImageHandler to render text from a querystring parameter. This text would display in the resulting image a...