Dotnetnuke
Vendor:
First CVE: Dec 31, 2004 · Active for 21 years
76
Total CVEs
More Total CVEs than 99% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
3.9%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Dotnetnuke over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Apr 17, 2026
98 days ago
CVE Severity & Scoring
Dotnetnuke76 CVEs
71%
22%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network50 (65.8%)
Unknown26 (34.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (64.5%)
High1 (1.3%)
Unknown26 (34.2%)
User Interaction
None24 (31.6%)
Unknown26 (34.2%)
Required26 (34.2%)
Privileges Required
Low22 (28.9%)
High4 (5.3%)
None24 (31.6%)
Unknown26 (34.2%)
Top CVEs
Signals from CVEs in this product scope (76 CVEs).
76 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9822HIGH DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites." | Jul 20, 2017 | 8.8 | 98 | YES | YES |
CVE-2018-18325HIGH DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811. | Jul 3, 2019 | 7.5 | 97 | YES | YES |
CVE-2018-15811HIGH DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. | Jul 3, 2019 | 7.5 | 97 | YES | YES |
CVE-2015-2794CRITICAL The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizar | Feb 6, 2017 | 9.8 | 81 | NO | YES |
CVE-2025-64095CRITICAL DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticat | Oct 28, 2025 | 9.8 | 72 | NO | YES |
CVE-2018-18326HIGH DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete | Jul 3, 2019 | 7.5 | 71 | NO | YES |
CVE-2018-15812HIGH DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy. | Jul 3, 2019 | 7.5 | 69 | NO | YES |
CVE-2025-52488HIGH DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially cr | Jun 21, 2025 | 8.6 | 57 | NO | YES |
CVE-2017-0929HIGH DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about in | Jul 3, 2018 | 7.5 | 35 | NO | YES |
CVE-2019-12562MEDIUM Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit c | Sep 26, 2019 | 6.1 | 34 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (76 CVEs).
CISA KEV
3 CVEs
3.9% of CVEs· 97th percentile
Metasploit
5 CVEs
6.6% of CVEs· 97th percentile
Nuclei
7 CVEs
9.2% of CVEs· 97th percentile
ExploitDB
11 CVEs
14.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (76 CVEs).
Media Mentions
Signals from CVEs in this product scope (76 CVEs).
Top CNAs Publishing CVEs For Dotnetnuke
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.5.0 | 1 | 4.3 | 0.7% | 0 | 0 |
| 9.1.1 | 1 | 6.1 | 1.1% | 0 | 0 |
| 7.1.0 | 3 | 4.0 | 1.5% | 0 | 0 |
| 7.0.6 | 3 | 4.0 | 1.5% | 0 | 0 |
| 7.0.5 | 3 | 4.0 | 1.5% | 0 | 0 |
| 7.0.4 | 3 | 4.0 | 1.5% | 0 | 0 |
| 7.0.3 | 3 | 4.0 | 1.5% | 0 | 0 |
| 7.0.2 | 3 | 4.0 | 1.5% | 0 | 0 |
| 7.0.1 | 3 | 4.0 | 1.5% | 0 | 0 |
| 7.0.0 | 3 | 4.0 | 1.5% | 0 | 0 |
| 6.2.7 | 3 | 4.0 | 1.5% | 0 | 0 |
| 6.2.6 | 3 | 4.0 | 1.5% | 0 | 0 |
| 6.2.5 | 3 | 4.0 | 1.5% | 0 | 0 |
| 6.2.4 | 3 | 4.0 | 1.5% | 0 | 0 |
| 6.2.3 | 3 | 4.0 | 1.5% | 0 | 0 |
| 6.2.2 | 3 | 4.0 | 1.5% | 0 | 0 |
| 6.2.1 | 3 | 4.0 | 1.5% | 0 | 0 |
| 6.2.0 | 3 | 4.0 | 1.5% | 0 | 0 |
| 6.1.5 | 3 | 4.0 | 1.5% | 0 | 0 |
| 6.1.4 | 3 | 4.0 | 1.5% | 0 | 0 |