Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28216 | DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline |
Github GHSA |
GHSA-m4hf-fxcg-cp34 | DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 26 Aug 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dnnsoftware
Dnnsoftware dotnetnuke |
|
| CPEs | cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dnnsoftware
Dnnsoftware dotnetnuke |
|
| Metrics |
cvssV3_1
|
Fri, 23 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 May 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Version 9.13.9 fixes the issue. | |
| Title | Dnn.Platform vulnerable to Stored Cross-Site Scripting (XSS) with svg files rendered inline | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-23T16:01:18.090Z
Reserved: 2025-05-19T15:46:00.396Z
Link: CVE-2025-48378
Updated: 2025-05-23T16:01:08.564Z
Status : Analyzed
Published: 2025-05-23T16:15:27.580
Modified: 2025-08-26T14:20:12.650
Link: CVE-2025-48378
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA