DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, module title supports richtext which could include scripts that would execute in certain scenarios. Versions 9.13.10 and 10.2.0 contain a fix for the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 28 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 Jan 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dnnsoftware
Dnnsoftware dnn Platform |
|
| Vendors & Products |
Dnnsoftware
Dnnsoftware dnn Platform |
Wed, 28 Jan 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, module title supports richtext which could include scripts that would execute in certain scenarios. Versions 9.13.10 and 10.2.0 contain a fix for the issue. | |
| Title | DotNetNuke.Core Vulnerable to Stored XSS via Module Title | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-01-27T23:58:33.340Z
Updated: 2026-01-28T15:03:27.676Z
Reserved: 2026-01-27T14:51:03.058Z
Link: CVE-2026-24838
Updated: 2026-01-28T15:03:22.746Z
Status : Received
Published: 2026-01-28T01:16:14.350
Modified: 2026-01-28T01:16:14.350
Link: CVE-2026-24838
No data.