Record summary

CVE-2025-48377 has a selected CVSS score of 6.0 (medium).

Description

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Version 9.13.9 fixes the issue.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 23, 2025 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List< 9.13.9affected
GitHub AdvisoryBefore 9.13.9 · Fixed in 9.13.9affected
GitHub AdvisoryBefore 9.13.9 · Fixed in 9.13.9affected

References

4