CVE-2025-59546

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, administrators and content editors can set html in module titles that could include javascript which could be used for XSS based attacks. This issue has been patched in version 10.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*

History

29 Sep 2025, 12:56

Type Values Removed Values Added
CPE cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*
References () https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-gj8m-5492-q98h - () https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-gj8m-5492-q98h - Vendor Advisory
First Time Dnnsoftware dotnetnuke
Dnnsoftware

23 Sep 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-23 18:15

Updated : 2025-09-29 12:56


NVD link : CVE-2025-59546

Mitre link : CVE-2025-59546

CVE.ORG link : CVE-2025-59546


JSON object : View

Products Affected

dnnsoftware

  • dotnetnuke
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')