Vulnerability index

Browse CVEs

52 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dotnetnuke MEDIUM 6.5
CVE-2020-5188

DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.

Fix: after 9.4.4
Fix from $1,600 2020-02-24
Dotnetnuke MEDIUM 5.4
CVE-2020-5186

DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).

Fix: after 9.4.4
Fix from $1,600 2020-02-24
Dotnetnuke MEDIUM 6.1
CVE-2019-12562EPSS 6%

Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin n…

Fix: 9.4.0+
Fix from $1,600 2019-09-26
Dotnetnuke HIGH 7.5
CVE-2018-15811 KEVEPSS 74%

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

Fix: after 9.2.1
Fix from $1,950 2019-07-03
Dotnetnuke HIGH 7.5
CVE-2018-15812EPSS 47%

DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.

Fix: after 9.2.1
Fix from $1,950 2019-07-03
Dotnetnuke HIGH 7.5
CVE-2018-18325 KEVEPSS 74%

DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete…

Fix: after 9.2.2
Fix from $1,950 2019-07-03
Dotnetnuke HIGH 7.5
CVE-2018-18326EPSS 54%

DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue …

Fix: after 9.2.2
Fix from $1,950 2019-07-03
Dotnetnuke MEDIUM 6.1
CVE-2018-14486

DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.

No fix yet
Fix from $1,600 2019-03-21
Dotnetnuke HIGH 7.5
CVE-2017-0929EPSS 13%

DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able…

Fix: 9.2.0+
Fix from $1,950 2018-07-03
Dotnetnuke HIGH 8.8
CVE-2017-9822 KEVEPSS 95%

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

Fix: 9.1.1+
Fix from $1,950 2017-07-20
Dotnetnuke CRITICAL 9.8
CVE-2015-2794EPSS 75%

The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct …

Fix: after 07.04.00
Fix from $2,300 2017-02-06
Dotnetnuke MEDIUM 5.4
CVE-2016-7119

Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to …

Fix: after 08.00.04
Fix from $1,600 2016-08-31
Dotnetnuke MEDIUM 5.0
CVE-2009-4109

The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need…

Mitigation only
Fix from $1,600 2009-11-29
Dotnetnuke HIGH 7.5
CVE-2008-7102

DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality, via unk…

Patch available
Fix from $1,950 2009-08-27
Dotnetnuke MEDIUM 6.5
CVE-2008-7100

Unspecified vulnerability in DotNetNuke 4.4.1 through 4.8.4 allows remote authenticated users to bypass authentication and gain privileges via unknow…

Patch available
Fix from $1,600 2009-08-27
Dotnetnuke MEDIUM 5.0
CVE-2008-7101

Unspecified vulnerability in DotNetNuke 4.0 through 4.8.4 and 5.0 allows remote attackers to obtain sensitive information (portal number) by accessin…

Patch available
Fix from $1,600 2009-08-27
Dotnetnuke MEDIUM 6.8
CVE-2008-6541

Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files a…

Fix: after 4.8.1
Fix from $1,600 2009-03-30
Dotnetnuke MEDIUM 5.1
CVE-2008-6540

DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey val…

Fix: after 4.8.1
Fix from $1,600 2009-03-30
Dotnetnuke MEDIUM 6.4
CVE-2008-6399

Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack …

Mitigation only
Fix from $1,600 2009-03-05
Dotnetnuke HIGH 10.0
CVE-2006-3601

** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privile…

No fix yet
Fix from $1,950 2006-07-18
Dotnetnuke HIGH 7.5
CVE-2004-2324

SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database vi…

Patch available
Fix from $1,950 2004-12-31
Dotnetnuke MEDIUM 5.0
CVE-2004-2323

DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server userna…

Patch available
Fix from $1,600 2004-12-31