CVE-2025-59535

MEDIUM

Dnnsoftware Dotnetnuke < 10.1.0 - Information Disclosure

Title source: rule
STIX 2.1

Description

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. This issue has been patched in version 10.1.0.

Scores

CVSS v3 6.5
EPSS 0.0010
EPSS Percentile 26.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-829 CWE-20 CWE-200
Status published
Products (2)
dnnsoftware/dotnetnuke < 10.1.0
nuget/DotNetNuke.Core 0 - 10.1.0NuGet
Published Sep 22, 2025
Tracked Since Feb 18, 2026