Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dnnsoftware

First CVE: Dec 31, 2004Active for: 22 yearsTotal CVEs: 76
61.2
VTI Score
TOP TARGET

DNN Software maintains DotNetNuke, a widely deployed open-source content management and application framework that powers a broad range of web properties and serves as a platform for custom extensions and integrations. The vendor's vulnerability footprint, though concentrated in a single product, reflects the complexity of a server-side web platform: recurring disclosures cluster around input-handling and cross-site scripting weaknesses, coupled with issues around sensitive information exposure and insufficient input validation that are characteristic of large, extensible web applications. While the absolute volume of disclosures is moderate, DotNetNuke's prominence in the landscape and its role as a foundational platform for downstream customizations amplify the practical reach of each flaw. Vulnerabilities affecting this vendor frequently acquire public exploit code, underscoring the need for defenders to track patches closely and prioritize remediation in exposed instances. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
76
Total CVEs
More Total CVEs than 99% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked vendors
3.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Dnnsoftware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Apr 17, 2026
99 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (76 CVEs).

76 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-9822HIGH
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
Jul 20, 20178.898YESYES
CVE-2018-18325HIGH
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
Jul 3, 20197.597YESYES
CVE-2018-15811HIGH
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
Jul 3, 20197.597YESYES
CVE-2015-2794CRITICAL
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizar
Feb 6, 20179.881NOYES
CVE-2025-64095CRITICAL
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticat
Oct 28, 20259.872NOYES
CVE-2018-18326HIGH
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete
Jul 3, 20197.571NOYES
CVE-2018-15812HIGH
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
Jul 3, 20197.569NOYES
CVE-2025-52488HIGH
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially cr
Jun 21, 20258.657NOYES
CVE-2017-0929HIGH
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about in
Jul 3, 20187.535NOYES
CVE-2019-12562MEDIUM
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit c
Sep 26, 20196.134NOYES
View all 76 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products76 CVEs
71%
22%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network50 (65.8%)
Unknown26 (34.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (64.5%)
High1 (1.3%)
Unknown26 (34.2%)
User Interaction
None24 (31.6%)
Unknown26 (34.2%)
Required26 (34.2%)
Privileges Required
Low22 (28.9%)
High4 (5.3%)
None24 (31.6%)
Unknown26 (34.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (76 CVEs).

CISA KEV
3 CVEs
3.9% of CVEs· 99th percentile
Metasploit
5 CVEs
6.6% of CVEs· 98th percentile
Nuclei
7 CVEs
9.2% of CVEs· 96th percentile
ExploitDB
11 CVEs
14.5% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dnnsoftware.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dnnsoftware — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dnnsoftware's Products

View all 7 CNAs →

Top CWEs