DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Version 9.13.9 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Aug 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dnnsoftware
Dnnsoftware dotnetnuke |
|
CPEs | cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:* | |
Vendors & Products |
Dnnsoftware
Dnnsoftware dotnetnuke |
|
Metrics |
cvssV3_1
|
Fri, 23 May 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 23 May 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Version 9.13.9 fixes the issue. | |
Title | Dnn.Platform vulnerable to Stored Cross-Site Scripting (XSS) with svg files rendered inline | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-23T16:01:18.090Z
Reserved: 2025-05-19T15:46:00.396Z
Link: CVE-2025-48378

Updated: 2025-05-23T16:01:08.564Z

Status : Analyzed
Published: 2025-05-23T16:15:27.580
Modified: 2025-08-26T14:20:12.650
Link: CVE-2025-48378

No data.