Skip to content
Noroxi

dnnsoftware records

76 published records for vendor dnnsoftware.

All records

76 records
  • DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN site

    HighCVSS 8.8KEVWeaponizedEPSS 95%

    dnnsoftware · dotnetnukeJul 20, 2017

  • DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

    HighCVSS 7.5KEVWeaponizedEPSS 76%

    dnnsoftware · dotnetnukeJul 3, 2019

  • DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters.

    HighCVSS 7.5KEVWeaponizedEPSS 74%

    dnnsoftware · dotnetnukeJul 3, 2019

  • CVE-2015-2794
    62This week

    The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via

    CriticalCVSS 9.8Proof of conceptEPSS 75%

    dnnsoftware · dotnetnukeFeb 6, 2017

  • DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

    CriticalCVSS 9.8Proof of conceptEPSS 47%

    dnnsoftware · dotnetnukeOct 28, 2025

  • DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy.

    HighCVSS 7.5WeaponizedEPSS 54%

    dnnsoftware · dotnetnukeJul 3, 2019

  • DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input

    HighCVSS 8.6Proof of conceptEPSS 36%

    dnnsoftware · dotnetnukeJun 20, 2025

  • DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.

    HighCVSS 7.5WeaponizedEPSS 47%

    dnnsoftware · dotnetnukeJul 3, 2019

  • ** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gai

    CriticalCVSS 10.0No exploitEPSS 2%

    dnnsoftware · dotnetnukeJul 18, 2006

  • CVE-2020-5187
    36Monitor

    DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).

    HighCVSS 8.8No exploitEPSS 2%

    dnnsoftware · dotnetnukeFeb 24, 2020

  • DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module

    CriticalCVSS 9.0No exploitEPSS 0%

    dnnsoftware · dotnetnukeSep 23, 2025

  • DNN.PLATFORM possibly allows bypass of IP Filters

    HighCVSS 8.8No exploitEPSS 0%

    dnnsoftware · dotnetnukeJun 20, 2025

  • CVE-2017-0929
    34Monitor

    DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class.

    HighCVSS 7.5Proof of conceptEPSS 13%

    dnnsoftware · dotnetnukeJul 3, 2018

  • DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload

    HighCVSS 8.0No exploitEPSS 0%

    dnnsoftware · dotnetnukeApr 17, 2026

  • CVE-2008-7102
    30Monitor

    DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality

    HighCVSS 7.5No exploitEPSS 1%

    dnnsoftware · dotnetnukeAug 27, 2009

  • CVE-2004-2324
    30Monitor

    SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend da

    HighCVSS 7.5No exploitEPSS 1%

    dnnsoftware · dotnetnukeDec 31, 2004

  • DNN CMS Server-Side Request Forgery (SSRF)

    HighCVSS 7.5No exploitEPSS 1%

    dnnsoftware · dotnetnukeJun 2, 2022

  • Possible Denial of Service (DoS) in DNN.PLATFORM registration

    HighCVSS 7.5No exploitEPSS 0%

    dnnsoftware · dotnetnukeApr 9, 2025

  • Server-Side Request Forgery (SSRF) in DotNetNuke.Core

    HighCVSS 7.5No exploitEPSS 0%

    dnnsoftware · dotnetnukeApr 9, 2025

  • DNN does not check the contents of a file when uploading files

    HighCVSS 7.5No exploitEPSS 0%

    dnnsoftware · dotnetnukeApr 8, 2025

  • CVE-2020-5188
    27Monitor

    DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.

    MediumCVSS 6.5No exploitEPSS 2%

    dnnsoftware · dotnetnukeFeb 24, 2020

  • CVE-2008-6541
    27Monitor

    Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrar

    MediumCVSS 6.8No exploitEPSS 1%

    dnnsoftware · dotnetnukeMar 29, 2009

  • DNN has same HostGUID for all new installs

    MediumCVSS 6.9No exploitEPSS 0%

    dnnsoftware · dotnetnukeApr 17, 2026

  • Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into th

    MediumCVSS 6.1Proof of conceptEPSS 6%

    dnnsoftware · dotnetnukeSep 26, 2019

  • CVE-2008-6399
    26Monitor

    Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknow

    MediumCVSS 6.4No exploitEPSS 2%

    dnnsoftware · dotnetnukeMar 5, 2009