Dotnetnuke

Vendor:

First CVE: Dec 31, 2004 · Active for 21 years

76
Total CVEs
More Total CVEs than 99% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
3.9%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Dotnetnuke over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Apr 17, 2026
98 days ago

CVE Severity & Scoring

Dotnetnuke76 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network50 (65.8%)
Unknown26 (34.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (64.5%)
High1 (1.3%)
Unknown26 (34.2%)
User Interaction
None24 (31.6%)
Unknown26 (34.2%)
Required26 (34.2%)
Privileges Required
Low22 (28.9%)
High4 (5.3%)
None24 (31.6%)
Unknown26 (34.2%)

Top CVEs

Signals from CVEs in this product scope (76 CVEs).

76 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
Jul 20, 20178.898YESYES
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
Jul 3, 20197.597YESYES
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
Jul 3, 20197.597YESYES
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizar
Feb 6, 20179.881NOYES
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticat
Oct 28, 20259.872NOYES
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete
Jul 3, 20197.571NOYES
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
Jul 3, 20197.569NOYES
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially cr
Jun 21, 20258.657NOYES
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about in
Jul 3, 20187.535NOYES
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit c
Sep 26, 20196.134NOYES

Exploit Exposure

Signals from CVEs in this product scope (76 CVEs).

CISA KEV
3 CVEs
3.9% of CVEs· 97th percentile
Metasploit
5 CVEs
6.6% of CVEs· 97th percentile
Nuclei
7 CVEs
9.2% of CVEs· 97th percentile
ExploitDB
11 CVEs
14.5% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (76 CVEs).

Media Mentions

Signals from CVEs in this product scope (76 CVEs).

Top CNAs Publishing CVEs For Dotnetnuke

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.5.014.30.7%00
9.1.116.11.1%00
7.1.034.01.5%00
7.0.634.01.5%00
7.0.534.01.5%00
7.0.434.01.5%00
7.0.334.01.5%00
7.0.234.01.5%00
7.0.134.01.5%00
7.0.034.01.5%00
6.2.734.01.5%00
6.2.634.01.5%00
6.2.534.01.5%00
6.2.434.01.5%00
6.2.334.01.5%00
6.2.234.01.5%00
6.2.134.01.5%00
6.2.034.01.5%00
6.1.534.01.5%00
6.1.434.01.5%00