CVE-2026-24833: DotNetNuke.Core Vulnerable to Stored XSS in Module Description
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, a module could install with richtext in its description field which could contain scripts that will run for user in the Persona Bar. Versions 9.13.10 and 10.2.0 contain a fix for the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24833?
CVE-2026-24833 has a medium severity level due to its potential for stored cross-site scripting vulnerabilities.
How do I fix CVE-2026-24833?
To fix CVE-2026-24833, upgrade to DNN version 9.13.10 or 10.2.0 or later.
What does CVE-2026-24833 affect?
CVE-2026-24833 affects the DotNetNuke (DNN) web content management platform, specifically versions before 9.13.10 and 10.2.0.
What type of vulnerability is CVE-2026-24833?
CVE-2026-24833 is classified as a stored cross-site scripting (XSS) vulnerability.
Can CVE-2026-24833 be exploited remotely?
Yes, CVE-2026-24833 can be exploited remotely by attackers to run malicious scripts on the affected DNN instance.