-
-
Notifications
You must be signed in to change notification settings - Fork 763
Security: dnnsoftware/Dnn.Platform
Security Navigation
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
NTLM hash leakage via SMB Share Interaction with malicious user inputGHSA-mgfv-2362-jq96 published
Jun 20, 2025 by valadasHigh -
Possible Denial of Service (DoS) in DNN.PLATFORM registrationGHSA-vc6j-mcqj-rgfp published
Apr 8, 2025 by valadasModerate -
Possibly bypass of IP FiltersGHSA-fjhg-3mrh-mm7h published
Jun 20, 2025 by valadasHigh -
Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjectsGHSA-pf4h-vrv6-cmvr published
Jun 20, 2025 by valadasModerate -
Stored Cross-Site Scripting (XSS) possible with svg files rendered inlineGHSA-m4hf-fxcg-cp34 published
May 23, 2025 by valadasModerate -
Stored Cross-Site Scripting (XSS) in Activity FeedGHSA-wwc9-wmm3-2pmf published
Jun 20, 2025 by valadasModerate -
Reflected Cross-Site Scripting (XSS) in module actions in edit modeGHSA-79m3-rvx2-3qq9 published
May 23, 2025 by valadasModerate -
Site Import could use an external source with a crafted requestGHSA-62mf-vhhw-xmf8 published
May 23, 2025 by valadasLow -
A registered user may enumerate and access files they should not have access toGHSA-vxcm-4rwh-chpc published
Apr 8, 2025 by valadasModerate -
Server-Side Request Forgery (SSRF) in DotNetNuke.CoreGHSA-3f7v-qx94-666m published
Apr 8, 2025 by valadasModerate