PT-2025-39191 · Dotnetnuke · Dnn

Bdukes

·

Published

2025-02-19

·

Updated

2025-10-31

·

CVE-2025-59545

CVSS v3.1
9.0
VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DNN (formerly DotNetNuke) versions prior to 10.1.0
Description DNN (formerly DotNetNuke) is an open-source web content management platform. The Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, potentially leading to script execution (XSS).
Recommendations Update to version 10.1.0 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-02487
CVE-2025-59545
GHSA-2QXC-MF4X-WR29

Affected Products

Dnn