PT-2026-5039 · Dnn · Dnn
Valadas
·
Published
2026-01-27
·
Updated
2026-01-28
·
CVE-2026-24784
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DNN (formerly DotNetNuke) versions 9.0.0 through 9.13.9
DNN (formerly DotNetNuke) versions 10.0.0 through 10.1.x
Description
DNN (formerly DotNetNuke) is an open-source web content management platform. A content editor could inject scripts into module headers or footers, which would then execute for other users.
Recommendations
Update to version 9.13.10 or later.
Update to version 10.2.0 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dnn