FAIL › dossier
DotNetNuke (DNN)
VENDOR· dossier confidence 0%
DotNetNuke (DNN) is an open-source CMS with a history of critical and high-severity vulnerabilities, including critical RCEs actively exploited in ransomware attacks and high-severity XSS flaws, indicating systemic issues in input validation and cryptographic implementation.
PROFILE
CategoryCMSWhat they doDotNetNuke (DNN) is an open-source web content management platform (CMS) in the Microsoft ecosystem.
SECURITY POSTURE
DNN has a poor security track record with multiple critical and high-severity vulnerabilities, including critical RCEs actively exploited in ransomware attacks and high-severity XSS flaws, indicating systemic issues in input validation and cryptographic implementation.
Notable failures
- CVE-2017-9822 critical RCE via cookie deserialization
- CVE-2018-15811 high weak encryption flaw in CISA KEV
- CVE-2026-40321 high stored XSS via SVG upload
Patterns: repeated unpatched edge-device RCEs; weak cryptographic implementations; stored XSS via user-uploaded content
FAILURE HISTORY · 6
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2017-9822 | critical | DotNetNuke (DNN) allowed remote code execution via a cookie deserialization vulnerability, actively exploited in ransomware attacks and impacting DIB organizations using the platform for web content management. |
| 2021-11-03 | CVE-2017-9822 | critical | DotNetNuke (DNN) allowed remote code execution via a cookie deserialization vulnerability, actively exploited in ransomware attacks and impacting DIB organizations using the platform for web content management. |
| 2021-11-03 | CVE-2018-18325 | high | DotNetNuke used weak encryption to protect input parameters, an incomplete patch for CVE-2018-15811 that was actively exploited in the wild. |
| 2021-11-03 | CVE-2018-18325 | high | DotNetNuke used weak encryption to protect input parameters, an incomplete patch for CVE-2018-15811 that was actively exploited in the wild. |
| 2021-11-03 | CVE-2018-15811 | high | DotNetNuke used weak encryption to protect input parameters, a flaw listed in CISA's KEV catalog. |
| 2021-11-03 | CVE-2018-15811 | high | DotNetNuke used weak encryption to protect input parameters, a flaw listed in CISA's KEV catalog. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
…
negative
"DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters."
DOSSIER SOURCES
- Nuget/DotNetNuke.Core | GitLab Advisory Database (GLAD) · advisories.gitlab.com
- Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find · www.cvefind.com
- GitLab Advisory Database (GLAD) · advisories.gitlab.com
Open questions: Current patch status for CVE-2018-15811 · Recent vulnerability disclosures since 2021
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-23 03:55:55.446173+00:00