-
-
Notifications
You must be signed in to change notification settings - Fork 770
Security: dnnsoftware/Dnn.Platform
Security Navigation
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Insufficient Access Control - Image Upload allows for Site Content OverwriteGHSA-3m8r-w7xg-jqvw published
Oct 28, 2025 by valadasCritical -
Stored cross-site-scripting (XSS) via SVG uploadGHSA-hmvq-8p83-cq52 published
Oct 28, 2025 by valadasModerate -
CKEditor Provider allows unauthenticated upload out-of-the-boxGHSA-2374-6cvw-qmx6 published
Oct 28, 2025 by valadasModerate -
Vulnerability in CKEditor's File Uploader functionality through Unicode obfuscationGHSA-cgqj-mw4m-v7hp published
Sep 23, 2025 by valadasModerate -
NTLM hash leakage via SMB Share Interaction with malicious user inputGHSA-mgfv-2362-jq96 published
Jun 20, 2025 by valadasHigh -
Stored XSS Using Backend Admin CredentialsGHSA-gj8m-5492-q98h published
Sep 23, 2025 by valadasLow -
Possible Denial of Service (DoS) in DNN.PLATFORM registrationGHSA-vc6j-mcqj-rgfp published
Apr 8, 2025 by valadasModerate -
Possibly bypass of IP FiltersGHSA-fjhg-3mrh-mm7h published
Jun 20, 2025 by valadasHigh -
Reflected Cross-Site Scripting (XSS) using url to profileGHSA-jc4g-c8ww-5738 published
Sep 23, 2025 by valadasModerate -
Stored Cross-Site Scripting (XSS) in Prompt moduleGHSA-2qxc-mf4x-wr29 published
Sep 22, 2025 by valadasCritical