dnnsoftware records
76 published records for vendor dnnsoftware.
Researcher profile
- Entered KEV
- 3 · 3.9%
- Weaponized
- 5 · 6.6%
- Pre-auth RCE
- 1
- With a fix record
- 59.2%
- Median publish → KEV
- 854 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')33
- CWE-20 Improper Input Validation4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-918 Server-Side Request Forgery (SSRF)3
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
The weakness classes this vendor ships most often: where to look.
CWEAll records
76 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
93Now | CVE-2017-9822Weaponized | DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sitednnsoftware · dotnetnuke · CWE-94 | High8.8 | KEV | 94.8% | Jul 20, 2017 |
83Now | CVE-2018-15811Weaponized | DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.dnnsoftware · dotnetnuke · CWE-326 | High7.5 | KEV | 76.1% | Jul 3, 2019 |
82Now | CVE-2018-18325Weaponized | DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters.dnnsoftware · dotnetnuke · CWE-326 | High7.5 | KEV | 73.9% | Jul 3, 2019 |
62This week | CVE-2015-2794Proof of concept | The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via dnnsoftware · dotnetnuke · CWE-264 | Critical9.8 | — | 75.1% | Feb 6, 2017 |
53Plan | CVE-2025-64095Proof of concept | DNN Insufficient Access Control - Image Upload allows for Site Content Overwritednnsoftware · dotnetnuke · CWE-434 | Critical9.8 | — | 47.0% | Oct 28, 2025 |
46Plan | CVE-2018-18326Weaponized | DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy.dnnsoftware · dotnetnuke · CWE-331 | High7.5 | — | 54.3% | Jul 3, 2019 |
45Plan | CVE-2025-52488Proof of concept | DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user inputdnnsoftware · dotnetnuke · CWE-200 | High8.6 | — | 35.8% | Jun 20, 2025 |
44Plan | CVE-2018-15812Weaponized | DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.dnnsoftware · dotnetnuke · CWE-331 | High7.5 | — | 47.2% | Jul 3, 2019 |
41Plan | CVE-2006-3601No exploit | ** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gaidnnsoftware · dotnetnuke | Critical10.0 | — | 2.5% | Jul 18, 2006 |
36Monitor | CVE-2020-5187No exploit | DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).dnnsoftware · dotnetnuke · CWE-22 | High8.8 | — | 2.4% | Feb 24, 2020 |
36Monitor | CVE-2025-59545No exploit | DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt modulednnsoftware · dotnetnuke · CWE-79 | Critical9.0 | — | 0.5% | Sep 23, 2025 |
35Monitor | CVE-2025-52487No exploit | DNN.PLATFORM possibly allows bypass of IP Filtersdnnsoftware · dotnetnuke · CWE-863 | High8.8 | — | 0.3% | Jun 20, 2025 |
34Monitor | CVE-2017-0929Proof of concept | DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class.dnnsoftware · dotnetnuke · CWE-918 | High7.5 | — | 12.5% | Jul 3, 2018 |
32Monitor | CVE-2026-40321No exploit | DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG uploaddnnsoftware · dotnetnuke · CWE-87 | High8.0 | — | 0.4% | Apr 17, 2026 |
30Monitor | CVE-2008-7102No exploit | DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionalitydnnsoftware · dotnetnuke · CWE-20 | High7.5 | — | 1.4% | Aug 27, 2009 |
30Monitor | CVE-2004-2324No exploit | SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend dadnnsoftware · dotnetnuke | High7.5 | — | 1.2% | Dec 31, 2004 |
30Monitor | CVE-2021-40186No exploit | DNN CMS Server-Side Request Forgery (SSRF)dnnsoftware · dotnetnuke · CWE-918 | High7.5 | — | 1.1% | Jun 2, 2022 |
30Monitor | CVE-2025-32374No exploit | Possible Denial of Service (DoS) in DNN.PLATFORM registrationdnnsoftware · dotnetnuke · CWE-770 | High7.5 | — | 0.4% | Apr 9, 2025 |
30Monitor | CVE-2025-32372No exploit | Server-Side Request Forgery (SSRF) in DotNetNuke.Corednnsoftware · dotnetnuke · CWE-918 | High7.5 | — | 0.4% | Apr 9, 2025 |
30Monitor | CVE-2025-32035No exploit | DNN does not check the contents of a file when uploading filesdnnsoftware · dotnetnuke · CWE-351 | High7.5 | — | 0.2% | Apr 8, 2025 |
27Monitor | CVE-2020-5188No exploit | DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.dnnsoftware · dotnetnuke · CWE-434 | Medium6.5 | — | 1.9% | Feb 24, 2020 |
27Monitor | CVE-2008-6541No exploit | Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrardnnsoftware · dotnetnuke · CWE-20 | Medium6.8 | — | 1.0% | Mar 29, 2009 |
27Monitor | CVE-2026-40306No exploit | DNN has same HostGUID for all new installsdnnsoftware · dotnetnuke · CWE-330 | Medium6.9 | — | 0.3% | Apr 17, 2026 |
26Monitor | CVE-2019-12562Proof of concept | Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into thdnnsoftware · dotnetnuke · CWE-79 | Medium6.1 | — | 6.2% | Sep 26, 2019 |
26Monitor | CVE-2008-6399No exploit | Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknowdnnsoftware · dotnetnuke · CWE-264 | Medium6.4 | — | 1.9% | Mar 5, 2009 |
- CVE-2017-982293Now
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN site
HighCVSS 8.8KEVWeaponizedEPSS 95%dnnsoftware · dotnetnukeJul 20, 2017
- CVE-2018-1581183Now
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
HighCVSS 7.5KEVWeaponizedEPSS 76%dnnsoftware · dotnetnukeJul 3, 2019
- CVE-2018-1832582Now
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters.
HighCVSS 7.5KEVWeaponizedEPSS 74%dnnsoftware · dotnetnukeJul 3, 2019
- CVE-2015-279462This week
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via
CriticalCVSS 9.8Proof of conceptEPSS 75%dnnsoftware · dotnetnukeFeb 6, 2017
- CVE-2025-6409553Plan
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
CriticalCVSS 9.8Proof of conceptEPSS 47%dnnsoftware · dotnetnukeOct 28, 2025
- CVE-2018-1832646Plan
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy.
HighCVSS 7.5WeaponizedEPSS 54%dnnsoftware · dotnetnukeJul 3, 2019
- CVE-2025-5248845Plan
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
HighCVSS 8.6Proof of conceptEPSS 36%dnnsoftware · dotnetnukeJun 20, 2025
- CVE-2018-1581244Plan
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
HighCVSS 7.5WeaponizedEPSS 47%dnnsoftware · dotnetnukeJul 3, 2019
- CVE-2006-360141Plan
** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gai
CriticalCVSS 10.0No exploitEPSS 2%dnnsoftware · dotnetnukeJul 18, 2006
- CVE-2020-518736Monitor
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
HighCVSS 8.8No exploitEPSS 2%dnnsoftware · dotnetnukeFeb 24, 2020
- CVE-2025-5954536Monitor
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
CriticalCVSS 9.0No exploitEPSS 0%dnnsoftware · dotnetnukeSep 23, 2025
- CVE-2025-5248735Monitor
DNN.PLATFORM possibly allows bypass of IP Filters
HighCVSS 8.8No exploitEPSS 0%dnnsoftware · dotnetnukeJun 20, 2025
- CVE-2017-092934Monitor
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class.
HighCVSS 7.5Proof of conceptEPSS 13%dnnsoftware · dotnetnukeJul 3, 2018
- CVE-2026-4032132Monitor
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
HighCVSS 8.0No exploitEPSS 0%dnnsoftware · dotnetnukeApr 17, 2026
- CVE-2008-710230Monitor
DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality
HighCVSS 7.5No exploitEPSS 1%dnnsoftware · dotnetnukeAug 27, 2009
- CVE-2004-232430Monitor
SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend da
HighCVSS 7.5No exploitEPSS 1%dnnsoftware · dotnetnukeDec 31, 2004
- CVE-2021-4018630Monitor
DNN CMS Server-Side Request Forgery (SSRF)
HighCVSS 7.5No exploitEPSS 1%dnnsoftware · dotnetnukeJun 2, 2022
- CVE-2025-3237430Monitor
Possible Denial of Service (DoS) in DNN.PLATFORM registration
HighCVSS 7.5No exploitEPSS 0%dnnsoftware · dotnetnukeApr 9, 2025
- CVE-2025-3237230Monitor
Server-Side Request Forgery (SSRF) in DotNetNuke.Core
HighCVSS 7.5No exploitEPSS 0%dnnsoftware · dotnetnukeApr 9, 2025
- CVE-2025-3203530Monitor
DNN does not check the contents of a file when uploading files
HighCVSS 7.5No exploitEPSS 0%dnnsoftware · dotnetnukeApr 8, 2025
- CVE-2020-518827Monitor
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
MediumCVSS 6.5No exploitEPSS 2%dnnsoftware · dotnetnukeFeb 24, 2020
- CVE-2008-654127Monitor
Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrar
MediumCVSS 6.8No exploitEPSS 1%dnnsoftware · dotnetnukeMar 29, 2009
- CVE-2026-4030627Monitor
DNN has same HostGUID for all new installs
MediumCVSS 6.9No exploitEPSS 0%dnnsoftware · dotnetnukeApr 17, 2026
- CVE-2019-1256226Monitor
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into th
MediumCVSS 6.1Proof of conceptEPSS 6%dnnsoftware · dotnetnukeSep 26, 2019
- CVE-2008-639926Monitor
Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknow
MediumCVSS 6.4No exploitEPSS 2%dnnsoftware · dotnetnukeMar 5, 2009