Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40321

31
FAUCET Score

DNN (DotNetNuke) versions prior to 10.2.2 contain a stored cross-site scripting vulnerability that allows authenticated users to upload specially crafted SVG files containing executable scripts. These scripts can be triggered against both authenticated and unauthenticated users, with heightened risk if executed by privileged users. The vulnerability affects this popular open-source content management platform widely used in Microsoft ecosystems. The vulnerability carries a CVSS score of 8.0 (HIGH) with a network-based attack vector requiring low authentication privileges and user interaction. The attack complexity is moderate, and successful exploitation could result in high-impact consequences including confidentiality, integrity, and availability compromise. The FAUCET Risk Score of 49.0 indicates moderate overall risk when considering additional contextual factors. There is currently no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and remains inactive on the Hot List, suggesting minimal community attention or available public exploit code. Organizations should prioritize patching to version 10.2.2 as part of standard maintenance activities, though immediate emergency response is not warranted based on current exploitation status.

Impacted Technologies

VendorProductVersion(s)CPE
< 10.2.2CPE matchmatch criteria
cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.0HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
7.60%
Probability of exploitation in next 30 days
EPSS Percentile
93.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0760 is in the 99th percentile among its peer group of 102 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

nugetpatch availablevia ghsa
Product: DotNetNuke.CoreFixed in: 10.2.2
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

nugetGHSA-ffq7-898w-9jc4high

DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload

Apr 10, 2026

References

github.com / dnnsoftware/Dnn.Platform/releases/tag/v10.2.2
Release Notes
github.com / dnnsoftware/Dnn.Platform/security/advisories/GHSA-ffq7-898w-9jc4
Vendor Advisory