dnnsoftware Vulnerabilities and Affected Products
Vulnerabilities associated with DotNetNuke (DNN).
Products
Clear product- Dnn.Platform31 vulnerabilities
- DotNetNuke (DNN)3 vulnerabilities
- DNN Platform1 vulnerability
- dnnsoftware/dnn.platform1 vulnerability
- DotNetNuke1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-64095CRITICAL | DNN Insufficient Access Control - Image Upload allows for Site Content OverwriteDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files allowing defacing a website and combined with other issue, injection XSS payloads. This vulnerability is fixed in 10.1.1. | CVSS10.0v3.1 | EPSS44.7% | PoCs3 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2025-52488HIGH | DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user inputDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version 10.0.1. | CVSS8.6v3.1 | EPSS32% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2017-0929HIGH | High severity vulnerability that affects DotNetNuke.CoreDNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources. | CVSS7.5v3.0 | EPSS12.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |