PT-2026-5043 · Dotnetnuke · Dnn

Bdukes

·

Published

2026-01-27

·

Updated

2026-02-02

·

CVE-2026-24838

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DNN (formerly DotNetNuke) versions prior to 9.13.10 DNN (formerly DotNetNuke) versions prior to 10.2.0
Description DNN (formerly DotNetNuke) is an open-source web content management platform. Prior to versions 9.13.10 and 10.2.0, the module title field allowed rich text, which could include scripts that could execute under certain conditions.
Recommendations Update to DNN version 9.13.10 or later. Update to DNN version 10.2.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-24838
GHSA-W9PF-H6M6-V89H

Affected Products

Dnn