DNN Software maintains DotNetNuke, a widely deployed open-source content management and application framework that powers a broad range of web properties and serves as a platform for custom extensions and integrations. The vendor's vulnerability footprint, though concentrated in a single product, reflects the complexity of a server-side web platform: recurring disclosures cluster around input-handling and cross-site scripting weaknesses, coupled with issues around sensitive information exposure and insufficient input validation that are characteristic of large, extensible web applications. While the absolute volume of disclosures is moderate, DotNetNuke's prominence in the landscape and its role as a foundational platform for downstream customizations amplify the practical reach of each flaw. Vulnerabilities affecting this vendor frequently acquire public exploit code, underscoring the need for defenders to track patches closely and prioritize remediation in exposed instances. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dnnsoftware over time
Signals from CVEs in this vendor scope (76 CVEs).
76 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9822HIGH DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites." | Jul 20, 2017 | 8.8 | 98 | YES | YES |
CVE-2018-18325HIGH DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811. | Jul 3, 2019 | 7.5 | 97 | YES | YES |
CVE-2018-15811HIGH DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. | Jul 3, 2019 | 7.5 | 97 | YES | YES |
CVE-2015-2794CRITICAL The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizar | Feb 6, 2017 | 9.8 | 81 | NO | YES |
CVE-2025-64095CRITICAL DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticat | Oct 28, 2025 | 9.8 | 72 | NO | YES |
CVE-2018-18326HIGH DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete | Jul 3, 2019 | 7.5 | 71 | NO | YES |
CVE-2018-15812HIGH DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy. | Jul 3, 2019 | 7.5 | 69 | NO | YES |
CVE-2025-52488HIGH DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially cr | Jun 21, 2025 | 8.6 | 57 | NO | YES |
CVE-2017-0929HIGH DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about in | Jul 3, 2018 | 7.5 | 35 | NO | YES |
CVE-2019-12562MEDIUM Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit c | Sep 26, 2019 | 6.1 | 34 | NO | YES |
Signals from CVEs in this vendor scope (76 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dnnsoftware.
Media articles that mention a CVE ID that affects a product developed by Dnnsoftware — matched by CVE ID, not by vendor name.