DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed
Moderate severity
GitHub Reviewed
Published
Jun 20, 2025
in
dnnsoftware/Dnn.Platform
•
Updated Sep 15, 2025
Description
Published to the GitHub Advisory Database
Jun 20, 2025
Reviewed
Jun 20, 2025
Published by the National Vulnerability Database
Jun 21, 2025
Last updated
Sep 15, 2025
DNN.PLATFORM allows a specially crafted request can inject scripts in the Activity Feed Attachments endpoint which will then render in the feed, resulting in a cross-site scripting attack. This vulnerability is fixed in 10.0.1.
References