CVE-2026-24784: DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
Published Jan 27, 2026
·Updated
A content editor could inject scripts in module headers/footers that would run for other users.
Affected Software
5 affected componentsFixes available
Microsoft DNN<9.13.10, <10.2.0
nuget/DotNetNuke.Core>=10.0.0<10.2.0
10.2.0
nuget/DotNetNuke.Core>=9.0.0<9.13.10
9.13.10
dnnsoftware Dotnetnuke>=9.0.0<9.13.10
dnnsoftware Dotnetnuke>=10.0.0<10.2.0
Event History
Jan 27, 2026
CVE Published
via MITRE·11:47 PM
Data Sourced
via MITRE·11:47 PM
DescriptionSeverityWeakness
Jan 28, 2026
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·04:20 PM
Data Sourced
via GitHub·04:20 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-24784?
CVE-2026-24784 has been classified as a critical severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2026-24784?
To remediate CVE-2026-24784, upgrade to DNN version 10.2.0 or 9.13.10.
3
What systems are affected by CVE-2026-24784?
CVE-2026-24784 affects Microsoft DNN versions prior to 9.13.10 and 10.2.0.
4
What type of vulnerability is CVE-2026-24784?
CVE-2026-24784 is classified as a potential cross-site scripting (XSS) vulnerability.
5
Who is impacted by CVE-2026-24784?
Users and administrators of DNN websites using vulnerable versions are at risk of this vulnerability.