CVE-2026-24837: DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
Published Jan 27, 2026
·Updated
A module friendly name could include scripts that will run during some module operations in the Persona Bar.
Affected Software
5 affected componentsFixes available
Microsoft DNN>9.0.0, <9.13.10, <10.2.0
nuget/DotNetNuke.Core>=10.0.0<10.2.0
10.2.0
nuget/DotNetNuke.Core>=9.0.0<=9.13.9
dnnsoftware Dotnetnuke>=9.0.0<9.13.10
dnnsoftware Dotnetnuke>=10.0.0<10.2.0
Event History
Jan 27, 2026
CVE Published
via MITRE·11:53 PM
Data Sourced
via MITRE·11:53 PM
DescriptionSeverityWeakness
Jan 28, 2026
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·04:34 PM
Data Sourced
via GitHub·04:34 PM
DescriptionSeverityWeaknessAffected Software
Feb 27, 58104
Event
via FIRST·09:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-24837?
CVE-2026-24837 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2026-24837?
To fix CVE-2026-24837, upgrade your DotNetNuke installation to version 10.2.0 or later.
3
What versions of DotNetNuke are affected by CVE-2026-24837?
CVE-2026-24837 affects DotNetNuke versions from 9.0.0 up to 9.13.10 and any version prior to 10.2.0.
4
What type of vulnerability is CVE-2026-24837?
CVE-2026-24837 is a stored cross-site scripting (XSS) vulnerability that can execute scripts in the context of the user’s session.
5
Can CVE-2026-24837 be exploited remotely?
Yes, CVE-2026-24837 can be exploited remotely by an attacker who can manipulate module friendly names to include malicious scripts.