Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/dnnsoftware/Dnn.Platform

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue.

Join the discussion

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from 9.x.x. Version 10.2.2 patches the issue.

Join the discussion

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue.

Join the discussion

CVE-2026-24838 is a critical cross-site scripting (XSS) vulnerability in the Dnn. Platform CMS affecting versions prior to 9.13.10 and between 10.0.0 and 10.2.0. The issue arises because module titles support rich text input that can include malicious scripts, which execute in certain scenarios without user interaction. Exploitation requires authenticated access but can lead to complete compromise of confidentiality, integrity, and availability of affected systems.

Join the discussion

CVE-2026-24837 is a high-severity cross-site scripting (XSS) vulnerability in the Dnn. Platform CMS affecting versions from 9.0.0 up to but not including 9.13.10 and 10.2.0. The flaw arises because module friendly names can contain malicious scripts that execute during certain Persona Bar module operations. Exploitation requires authenticated users with high privileges and some user interaction, but can lead to complete compromise of confidentiality, integrity, and availability due to the scope of the vulnerability.

Join the discussion

CVE-2026-24836 is a high-severity cross-site scripting (XSS) vulnerability affecting Dnn. Platform versions from 9.0.0 up to but not including 9.13.10, and from 10.0.0 up to but not including 10.2.0.

Join the discussion

CVE-2026-24833 is a high-severity cross-site scripting (XSS) vulnerability in the Dnn. Platform CMS affecting versions prior to 9.13.10 and between 10.0.0 and 10.2.0. The flaw allows malicious scripts embedded in a module's richtext description field to execute within the Persona Bar interface, potentially compromising confidentiality, integrity, and availability. Exploitation requires authenticated access with high privileges and user interaction, but can lead to full session compromise and persistent code execution.

Join the discussion

CVE-2026-24784 is a cross-site scripting (XSS) vulnerability in the Dnn. Platform CMS affecting versions from 9.0.0 up to but not including 9.13.10 and 10.2.0. The flaw allows a content editor with module header/footer editing privileges to inject malicious scripts that execute in the browsers of other users. The vulnerability requires authenticated access with elevated privileges but does not require user interaction to trigger once the malicious content is loaded.

Join the discussion

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files allowing defacing a website and combined with other issue, injection XSS payloads. This vulnerability is fixed in 10.1.1.

Join the discussion

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, sanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. This vulnerability exists because of an incomplete fix for CVE-2025-48378. This vulnerability is fixed in 10.1.1.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Package: pkg:github/dnnsoftware/Dnn.Platform
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses