The .NET Foundation encompasses a narrow but architecturally prominent set of open-source projects and language tools, including the Piranha CMS platform and C# Language Server Protocol implementation, that serve development and content-management workloads. Its vulnerability exposure clusters around web-facing input handling and request-processing weaknesses—including cross-site scripting, cross-site request forgery, and resource-consumption issues—reflecting the application-layer and web-framework nature of these tools. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dotnetfoundation over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25976HIGH In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleti | Nov 16, 2021 | 8.1 | 25 | NO | NO |
CVE-2025-67291MEDIUM A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload | Dec 22, 2025 | 6.1 | 24 | NO | NO |
CVE-2025-67290MEDIUM A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted | Dec 22, 2025 | 6.1 | 24 | NO | NO |
CVE-2025-57692MEDIUM PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, enabling execution of arbitrary JavaScript in another user s | Sep 26, 2025 | 6.8 | 24 | NO | NO |
CVE-2025-61413MEDIUM A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers to execute arbitrary web scripts or HTML via creating a page | Oct 23, 2025 | 6.1 | 22 | NO | NO |
CVE-2021-25977MEDIUM In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privil | Oct 25, 2021 | 5.4 | 20 | NO | NO |
CVE-2022-4952HIGH A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSett | Jul 17, 2023 | 7.5 | 19 | NO | NO |
CVE-2024-55341MEDIUM A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by creating a page via t | Dec 20, 2024 | 4.7 | 16 | NO | NO |
CVE-2024-55342MEDIUM A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media. This PDF can contain malicious JavaScript code | Dec 20, 2024 | 4.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dotnetfoundation.
Media articles that mention a CVE ID that affects a product developed by Dotnetfoundation — matched by CVE ID, not by vendor name.