Skip to content
COOEY

FAIL › dossier

DotNetNuke (DNN)

VENDOR

· dossier confidence 0%

DotNetNuke (DNN) is an open-source CMS with a history of critical and high-severity vulnerabilities, including critical RCEs actively exploited in ransomware attacks and high-severity XSS flaws, indicating systemic issues in input validation and cryptographic implementation.

PROFILE
CategoryCMSWhat they doDotNetNuke (DNN) is an open-source web content management platform (CMS) in the Microsoft ecosystem.
SECURITY POSTURE

DNN has a poor security track record with multiple critical and high-severity vulnerabilities, including critical RCEs actively exploited in ransomware attacks and high-severity XSS flaws, indicating systemic issues in input validation and cryptographic implementation.

Notable failures
  • CVE-2017-9822 critical RCE via cookie deserialization
  • CVE-2018-15811 high weak encryption flaw in CISA KEV
  • CVE-2026-40321 high stored XSS via SVG upload
Patterns: repeated unpatched edge-device RCEs; weak cryptographic implementations; stored XSS via user-uploaded content
Reputationsevere-fallout (-0.80) · 3 trusted sources Coveragecooey · cooey · cooey
FAILURE HISTORY · 6
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2017-9822 critical DotNetNuke (DNN) allowed remote code execution via a cookie deserialization vulnerability, actively exploited in ransomware attacks and impacting DIB organizations using the platform for web content management.
2021-11-03 CVE-2017-9822 critical DotNetNuke (DNN) allowed remote code execution via a cookie deserialization vulnerability, actively exploited in ransomware attacks and impacting DIB organizations using the platform for web content management.
2021-11-03 CVE-2018-18325 high DotNetNuke used weak encryption to protect input parameters, an incomplete patch for CVE-2018-15811 that was actively exploited in the wild.
2021-11-03 CVE-2018-18325 high DotNetNuke used weak encryption to protect input parameters, an incomplete patch for CVE-2018-15811 that was actively exploited in the wild.
2021-11-03 CVE-2018-15811 high DotNetNuke used weak encryption to protect input parameters, a flaw listed in CISA's KEV catalog.
2021-11-03 CVE-2018-15811 high DotNetNuke used weak encryption to protect input parameters, a flaw listed in CISA's KEV catalog.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
cooey ↗severe-fallout-1.00
negative
"DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters."
cooey ↗severe-fallout-0.70
"…"
cooey ↗severe-fallout-0.70
"…"
Open questions: Current patch status for CVE-2018-15811 · Recent vulnerability disclosures since 2021
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-23 03:55:55.446173+00:00