CVE-2026-24838: DotNetNuke.Core Vulnerable to Stored XSS via Module Title
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, module title supports richtext which could include scripts that would execute in certain scenarios. Versions 9.13.10 and 10.2.0 contain a fix for the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24838?
CVE-2026-24838 has been classified as a medium severity vulnerability due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2026-24838?
To resolve CVE-2026-24838, upgrade to DotNetNuke versions 9.13.10 or 10.2.0 or later.
What is the impact of CVE-2026-24838 on my DNN installation?
CVE-2026-24838 allows attackers to execute scripts through manipulated module titles, potentially compromising user data and sessions.
Is my DNN version vulnerable to CVE-2026-24838?
DNN versions prior to 9.13.10 and 10.2.0 are affected by CVE-2026-24838 and are vulnerable to this exploit.
Who is affected by CVE-2026-24838?
Any user of DotNetNuke versions earlier than 9.13.10 and 10.2.0 is potentially affected by CVE-2026-24838.