dnnsoftware kayıtları
dnnsoftware üreticisine ait 76 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 3 · %3,9
- Silahlaştırılmış
- 5 · %6,6
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %59,2
- Yayından KEV’e ortanca
- 854 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')33
- CWE-20 Improper Input Validation4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-918 Server-Side Request Forgery (SSRF)3
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
76 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
93Hemen | CVE-2017-9822Silahlaştırılmış | DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sitednnsoftware · dotnetnuke · CWE-94 | Yüksek8,8 | KEV | %94,8 | 20 Tem 2017 |
83Hemen | CVE-2018-15811Silahlaştırılmış | DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.dnnsoftware · dotnetnuke · CWE-326 | Yüksek7,5 | KEV | %76,1 | 3 Tem 2019 |
82Hemen | CVE-2018-18325Silahlaştırılmış | DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters.dnnsoftware · dotnetnuke · CWE-326 | Yüksek7,5 | KEV | %73,9 | 3 Tem 2019 |
62Bu hafta | CVE-2015-2794Kavram kanıtı | The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via dnnsoftware · dotnetnuke · CWE-264 | Kritik9,8 | — | %75,1 | 6 Şub 2017 |
53Planlayın | CVE-2025-64095Kavram kanıtı | DNN Insufficient Access Control - Image Upload allows for Site Content Overwritednnsoftware · dotnetnuke · CWE-434 | Kritik9,8 | — | %47,0 | 28 Eki 2025 |
46Planlayın | CVE-2018-18326Silahlaştırılmış | DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy.dnnsoftware · dotnetnuke · CWE-331 | Yüksek7,5 | — | %54,3 | 3 Tem 2019 |
45Planlayın | CVE-2025-52488Kavram kanıtı | DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user inputdnnsoftware · dotnetnuke · CWE-200 | Yüksek8,6 | — | %35,8 | 20 Haz 2025 |
44Planlayın | CVE-2018-15812Silahlaştırılmış | DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.dnnsoftware · dotnetnuke · CWE-331 | Yüksek7,5 | — | %47,2 | 3 Tem 2019 |
41Planlayın | CVE-2006-3601İstismar yok | ** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gaidnnsoftware · dotnetnuke | Kritik10,0 | — | %2,5 | 18 Tem 2006 |
36İzleyin | CVE-2020-5187İstismar yok | DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).dnnsoftware · dotnetnuke · CWE-22 | Yüksek8,8 | — | %2,4 | 24 Şub 2020 |
36İzleyin | CVE-2025-59545İstismar yok | DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt modulednnsoftware · dotnetnuke · CWE-79 | Kritik9,0 | — | %0,5 | 23 Eyl 2025 |
35İzleyin | CVE-2025-52487İstismar yok | DNN.PLATFORM possibly allows bypass of IP Filtersdnnsoftware · dotnetnuke · CWE-863 | Yüksek8,8 | — | %0,3 | 20 Haz 2025 |
34İzleyin | CVE-2017-0929Kavram kanıtı | DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class.dnnsoftware · dotnetnuke · CWE-918 | Yüksek7,5 | — | %12,5 | 3 Tem 2018 |
32İzleyin | CVE-2026-40321İstismar yok | DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG uploaddnnsoftware · dotnetnuke · CWE-87 | Yüksek8,0 | — | %0,4 | 17 Nis 2026 |
30İzleyin | CVE-2008-7102İstismar yok | DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionalitydnnsoftware · dotnetnuke · CWE-20 | Yüksek7,5 | — | %1,4 | 27 Ağu 2009 |
30İzleyin | CVE-2004-2324İstismar yok | SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend dadnnsoftware · dotnetnuke | Yüksek7,5 | — | %1,2 | 31 Ara 2004 |
30İzleyin | CVE-2021-40186İstismar yok | DNN CMS Server-Side Request Forgery (SSRF)dnnsoftware · dotnetnuke · CWE-918 | Yüksek7,5 | — | %1,1 | 2 Haz 2022 |
30İzleyin | CVE-2025-32374İstismar yok | Possible Denial of Service (DoS) in DNN.PLATFORM registrationdnnsoftware · dotnetnuke · CWE-770 | Yüksek7,5 | — | %0,4 | 9 Nis 2025 |
30İzleyin | CVE-2025-32372İstismar yok | Server-Side Request Forgery (SSRF) in DotNetNuke.Corednnsoftware · dotnetnuke · CWE-918 | Yüksek7,5 | — | %0,4 | 9 Nis 2025 |
30İzleyin | CVE-2025-32035İstismar yok | DNN does not check the contents of a file when uploading filesdnnsoftware · dotnetnuke · CWE-351 | Yüksek7,5 | — | %0,2 | 8 Nis 2025 |
27İzleyin | CVE-2020-5188İstismar yok | DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.dnnsoftware · dotnetnuke · CWE-434 | Orta6,5 | — | %1,9 | 24 Şub 2020 |
27İzleyin | CVE-2008-6541İstismar yok | Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrardnnsoftware · dotnetnuke · CWE-20 | Orta6,8 | — | %1,0 | 29 Mar 2009 |
27İzleyin | CVE-2026-40306İstismar yok | DNN has same HostGUID for all new installsdnnsoftware · dotnetnuke · CWE-330 | Orta6,9 | — | %0,3 | 17 Nis 2026 |
26İzleyin | CVE-2019-12562Kavram kanıtı | Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into thdnnsoftware · dotnetnuke · CWE-79 | Orta6,1 | — | %6,2 | 26 Eyl 2019 |
26İzleyin | CVE-2008-6399İstismar yok | Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknowdnnsoftware · dotnetnuke · CWE-264 | Orta6,4 | — | %1,9 | 5 Mar 2009 |
- CVE-2017-982293Hemen
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN site
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %95dnnsoftware · dotnetnuke20 Tem 2017
- CVE-2018-1581183Hemen
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %76dnnsoftware · dotnetnuke3 Tem 2019
- CVE-2018-1832582Hemen
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %74dnnsoftware · dotnetnuke3 Tem 2019
- CVE-2015-279462Bu hafta
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via
KritikCVSS 9,8Kavram kanıtıEPSS %75dnnsoftware · dotnetnuke6 Şub 2017
- CVE-2025-6409553Planlayın
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
KritikCVSS 9,8Kavram kanıtıEPSS %47dnnsoftware · dotnetnuke28 Eki 2025
- CVE-2018-1832646Planlayın
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy.
YüksekCVSS 7,5SilahlaştırılmışEPSS %54dnnsoftware · dotnetnuke3 Tem 2019
- CVE-2025-5248845Planlayın
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
YüksekCVSS 8,6Kavram kanıtıEPSS %36dnnsoftware · dotnetnuke20 Haz 2025
- CVE-2018-1581244Planlayın
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
YüksekCVSS 7,5SilahlaştırılmışEPSS %47dnnsoftware · dotnetnuke3 Tem 2019
- CVE-2006-360141Planlayın
** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gai
KritikCVSS 10,0İstismar yokEPSS %2dnnsoftware · dotnetnuke18 Tem 2006
- CVE-2020-518736İzleyin
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
YüksekCVSS 8,8İstismar yokEPSS %2dnnsoftware · dotnetnuke24 Şub 2020
- CVE-2025-5954536İzleyin
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
KritikCVSS 9,0İstismar yokEPSS %0dnnsoftware · dotnetnuke23 Eyl 2025
- CVE-2025-5248735İzleyin
DNN.PLATFORM possibly allows bypass of IP Filters
YüksekCVSS 8,8İstismar yokEPSS %0dnnsoftware · dotnetnuke20 Haz 2025
- CVE-2017-092934İzleyin
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class.
YüksekCVSS 7,5Kavram kanıtıEPSS %13dnnsoftware · dotnetnuke3 Tem 2018
- CVE-2026-4032132İzleyin
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
YüksekCVSS 8,0İstismar yokEPSS %0dnnsoftware · dotnetnuke17 Nis 2026
- CVE-2008-710230İzleyin
DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality
YüksekCVSS 7,5İstismar yokEPSS %1dnnsoftware · dotnetnuke27 Ağu 2009
- CVE-2004-232430İzleyin
SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend da
YüksekCVSS 7,5İstismar yokEPSS %1dnnsoftware · dotnetnuke31 Ara 2004
- CVE-2021-4018630İzleyin
DNN CMS Server-Side Request Forgery (SSRF)
YüksekCVSS 7,5İstismar yokEPSS %1dnnsoftware · dotnetnuke2 Haz 2022
- CVE-2025-3237430İzleyin
Possible Denial of Service (DoS) in DNN.PLATFORM registration
YüksekCVSS 7,5İstismar yokEPSS %0dnnsoftware · dotnetnuke9 Nis 2025
- CVE-2025-3237230İzleyin
Server-Side Request Forgery (SSRF) in DotNetNuke.Core
YüksekCVSS 7,5İstismar yokEPSS %0dnnsoftware · dotnetnuke9 Nis 2025
- CVE-2025-3203530İzleyin
DNN does not check the contents of a file when uploading files
YüksekCVSS 7,5İstismar yokEPSS %0dnnsoftware · dotnetnuke8 Nis 2025
- CVE-2020-518827İzleyin
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
OrtaCVSS 6,5İstismar yokEPSS %2dnnsoftware · dotnetnuke24 Şub 2020
- CVE-2008-654127İzleyin
Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrar
OrtaCVSS 6,8İstismar yokEPSS %1dnnsoftware · dotnetnuke29 Mar 2009
- CVE-2026-4030627İzleyin
DNN has same HostGUID for all new installs
OrtaCVSS 6,9İstismar yokEPSS %0dnnsoftware · dotnetnuke17 Nis 2026
- CVE-2019-1256226İzleyin
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into th
OrtaCVSS 6,1Kavram kanıtıEPSS %6dnnsoftware · dotnetnuke26 Eyl 2019
- CVE-2008-639926İzleyin
Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknow
OrtaCVSS 6,4İstismar yokEPSS %2dnnsoftware · dotnetnuke5 Mar 2009