Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
DNN CKEditor Provider allows unauthenticated upload out-of-the-box Moderate
CVE-2025-62802 was published for Dnn.Platform (NuGet) Oct 29, 2025
r90727 Credited to r90727, bdukes, donker, david-poindexter, and mitchelsellers bdukes bdukes
donker donker david-poindexter david-poindexter mitchelsellers mitchelsellers
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile Moderate
CVE-2025-59821 was published for DotNetNuke.Core (NuGet) Sep 23, 2025
bdukes Credited to bdukes, david-poindexter, and valadas david-poindexter david-poindexter
valadas valadas
DNN Vulnerable to Stored XSS Using Backend Admin Credentials Low
CVE-2025-59546 was published for DotNetNuke.Core (NuGet) Sep 23, 2025
bdukes Credited to bdukes, david-poindexter, and valadas david-poindexter david-poindexter
valadas valadas
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline Moderate
CVE-2025-48378 was published for DotNetNuke.Core (NuGet) May 23, 2025
bdukes Credited to bdukes, david-poindexter, and valadas david-poindexter david-poindexter
valadas valadas
Reflected Cross-Site Scripting (XSS) in module actions in edit mode Moderate
CVE-2025-48377 was published for DotNetNuke.Core (NuGet) May 23, 2025
bdukes Credited to bdukes, david-poindexter, and valadas david-poindexter david-poindexter
valadas valadas
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF) Moderate
CVE-2025-32372 was published for DotNetNuke.Core (NuGet) Apr 9, 2025
s0nnyWT Credited to s0nnyWT, valadas, and david-poindexter valadas valadas
david-poindexter david-poindexter
ProTip! Advisories are also available from the GraphQL API