DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Versions 9.13.10 and 10.2.0 contain a fix for the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 28 Jan 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dnnsoftware
Dnnsoftware dnn Platform |
|
| Vendors & Products |
Dnnsoftware
Dnnsoftware dnn Platform |
Wed, 28 Jan 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Versions 9.13.10 and 10.2.0 contain a fix for the issue. | |
| Title | DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-01-27T23:51:27.138Z
Updated: 2026-01-27T23:51:27.138Z
Reserved: 2026-01-27T14:51:03.058Z
Link: CVE-2026-24836
No data.
Status : Received
Published: 2026-01-28T00:15:50.910
Modified: 2026-01-28T00:15:50.910
Link: CVE-2026-24836
No data.