Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-52487


DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request or proxy to be created that could bypass the design of DNN Login IP Filters allowing login attempts from IP Addresses not in the allow list. This issue has been patched in version 10.0.1.


Published

2025-06-21T03:15:24.667

Last Modified

2025-09-15T15:30:48.727

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dnnsoftware dotnetnuke < 10.0.1 Yes

References