MEDIUM🇵🇱 Wersja polska

CVE-2025-32036

CVSS 4.2v3.1pub. 2025-04-08upd. 2025-08-26

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. The algorithm used to generate the captcha image shows the least complexity of the desired image. For this reason, the created image can be easily read by OCR tools, and the intruder can send automatic requests by building a robot and using this tool. This vulnerability is fixed in 9.13.8.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
  • Dnnsoftware Dotnetnuke

    APP
    Dnnsoftware
    < 9.13.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-24838CRITICAL9.1PL ✓same product

DNN/DotNetNuke: XSS w tytule modułu umożliwia wykonanie skryptów

CVE-2025-64095CRITICAL10.0PL ✓same product

DNN/DotNetNuke: nieuwierzytelnione przesyłanie i nadpisywanie plików (RCE/XSS)

CVE-2025-59545CRITICAL9.0PL ✓same product

XSS w module Prompt platformy DNN (DotNetNuke) — wykonanie skryptu

CVE-2015-2794CRITICAL9.8PL ✓same product

DotNetNuke: nieautoryzowana reinstalacja aplikacji i przejęcie konta SuperUser

CVE-2018-15811HIGH7.5⚠ KEVsame product

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.