Where
-Infinity
0

Vendor Risk Score

See how dnnsoftware compares to other vendors in security performance

View Risk Score →

nuget/DotNetNuke.CoreDNN has same HostGUID for all new installs

Risk 33
Severity
6.9
First published (updated )

nuget/DotNetNuke.CoreDNN has Force Friend Request Acceptance

Risk 22
Severity
4.3
First published (updated )

nuget/DotNetNuke.CoreDotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload

Risk 68
Severity
8.1
First published (updated )

DotNetNuke DotNetNukeDotNetNuke 9.5 - Persistent Cross-Site Scripting

Risk 39
Severity
5.1
First published (updated )

nuget/DotNetNuke.CoreDotNetNuke.Core Vulnerable to Stored XSS via Module Title

Risk 54
Severity
9.1
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

nuget/DotNetNuke.CoreDotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal

Risk 47
Severity
7.7
EPSS
0.01%
First published (updated )

nuget/DotNetNuke.CoreDotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes

Risk 47
Severity
7.7
EPSS
0.01%
First published (updated )

dnnsoftware DotnetnukeDotNetNuke.Core Vulnerable to Stored XSS in Module Description

Risk 47
Severity
7.7
EPSS
0.03%
First published (updated )

nuget/DotNetNuke.CoreDotNetNuke.Core has a potential XSS vulnerability in modules' header and footer

Risk 27
Severity
6.8
EPSS
0.03%
First published (updated )

DNN DNNDNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

Risk 87
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

DNN DNNDNN vulnerable to stored cross-site-scripting (XSS) via SVG upload

Risk 39
Severity
6.4
First published (updated )

DNN DNNDNN CKEditor Provider allows unauthenticated upload out-of-the-box

Risk 22
Severity
4.3
First published (updated )

DNN DNNDNN Vulnerable to Reflected Cross-Site Scripting (XSS) in CKEditor File Browser

Risk 38
Severity
6.1
First published (updated )

DNN DNNDNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscation

Risk 27
Severity
5.3
First published (updated )

nuget/DotNetNuke.CoreDNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile

Risk 37
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

nuget/DotNetNuke.CoreDNN Vulnerable to Stored XSS Using Backend Admin Credentials

Risk 29
Severity
4.8
First published (updated )

nuget/DotNetNuke.CoreDNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module

Risk 75
Severity
9.1
First published (updated )

dnnsoftware DotnetnukeDNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field

Risk 46
Severity
6.3
First published (updated )

DNN DotNetNukeDotNetNuke.Core allows loading of unused themes on anonymous clients through query parameters

Risk 40
Severity
6.5
First published (updated )

nuget/DNN.PLATFORMDNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input

Risk 34
Severity
8.6
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

nuget/DNN.PLATFORMDNN.PLATFORM possibly allows bypass of IP Filters

Risk 46
Severity
8.8
EPSS
0.05%
First published (updated )

nuget/DNN.PLATFORMDNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed

Risk 25
Severity
5.4
EPSS
0.04%
First published (updated )

nuget/DNN.PLATFORMDNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjects

Risk 28
Severity
6.1
EPSS
0.05%
First published (updated )

DNN Dnn.PlatformDnn.Platform vulnerable to Reflected Cross-Site Scripting (XSS) in module actions in edit mode

Risk 27
Severity
6
EPSS
0.05%
First published (updated )

DNN Dnn.PlatformDnn.Platform vulnerable to Stored Cross-Site Scripting (XSS) with svg files rendered inline

Risk 27
Severity
6.1
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

DNN Dnn.PlatformDnn.Platform's Site Import could use an external source with a crafted request

Risk 18
Severity
3.5
EPSS
0.03%
First published (updated )

DNN Dnn.PlatformPossible Denial of Service (DoS) in DNN.PLATFORM registration

Risk 31
Severity
7.5
EPSS
0.05%
First published (updated )

DNN DNNDNN allows a registered user to enumerate and access files they should not have access to

Risk 27
Severity
6.5
EPSS
0.03%
First published (updated )

DNN DNNUnexpected external content may be displayed in DNN ImageHandler

Risk 16
Severity
4.3
EPSS
0.03%
First published (updated )

nuget/DotNetNuke.CoreServer-Side Request Forgery (SSRF) in DotNetNuke.Core

Risk 31
Severity
7.5
EPSS
0.08%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203