Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-59546


DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, administrators and content editors can set html in module titles that could include javascript which could be used for XSS based attacks. This issue has been patched in version 10.1.0.


Published

2025-09-23T18:15:39.257

Last Modified

2025-09-29T12:56:28.353

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 2.4 (LOW)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dnnsoftware dotnetnuke < 10.1.0 Yes

References