CRITICAL🇵🇱 Wersja polska

CVE-2026-24838

CVSS 9.1v3.1pub. 2026-01-28upd. 2026-02-04

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, module title supports richtext which could include scripts that would execute in certain scenarios. Versions 9.13.10 and 10.2.0 contain a fix for the issue.

🤖 AI Analysis
How it works

The module title field in DNN accepts content in rich text format, which allows embedding malicious JavaScript code. In certain page rendering scenarios, the embedded script is executed by the user's browser without proper input sanitization. The vulnerability requires administrative privileges (PR:H) to inject the payload, however its impact extends beyond the attacker's context (Scope:Changed).

Impact

An attacker with administrator privileges can inject malicious scripts that will be executed in the context of other users' browsers, which may lead to session theft, account takeover, or sensitive data disclosure.

Mitigation & patch

DNN should be updated to version 9.13.10 or 10.2.0, which contain patches eliminating the vulnerability. Details are available in the vendor's references on GitHub Security Advisory.

Who is affected

DNN (DotNetNuke) in all versions before 9.13.10 and before 10.2.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Dnnsoftware Dotnetnuke

    APP
    Dnnsoftware
    < 9.13.1010.0.0 – 10.2.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2025-64095CRITICAL10.0PL ✓same product

DNN/DotNetNuke: nieuwierzytelnione przesyłanie i nadpisywanie plików (RCE/XSS)

CVE-2025-59545CRITICAL9.0PL ✓same product

XSS w module Prompt platformy DNN (DotNetNuke) — wykonanie skryptu

CVE-2015-2794CRITICAL9.8PL ✓same product

DotNetNuke: nieautoryzowana reinstalacja aplikacji i przejęcie konta SuperUser

CVE-2018-15811HIGH7.5⚠ KEVsame product

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

CVE-2018-18325HIGH7.5⚠ KEVsame product

DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: thi...