CVE-2025-59545

CRITICAL

Dnnsoftware Dotnetnuke < 10.1.0 - XSS

Title source: rule
STIX 2.1

Description

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). This issue has been patched in version 10.1.0.

References (1)

Core 1

Scores

CVSS v3 9.0
EPSS 0.0006
EPSS Percentile 20.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
dnnsoftware/dotnetnuke < 10.1.0
nuget/DotNetNuke.Core 0 - 10.1.0NuGet
Published Sep 23, 2025
Tracked Since Feb 18, 2026