CVE-2009-4110
DotNetNuke <5.1.4 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not properly filtered before display in a custom results page.
References (5)
Scores
EPSS
0.0032
EPSS Percentile
54.7%
Classification
CWE
CWE-79
Status
published
Affected Products (15)
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
dotnetnuke/dotnetnuke
n/a/n/a
Timeline
Published
Nov 29, 2009
Tracked Since
Feb 18, 2026