DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
High severity
GitHub Reviewed
Published
Apr 10, 2026
in
dnnsoftware/Dnn.Platform
•
Updated Apr 24, 2026
Description
Published to the GitHub Advisory Database
Apr 10, 2026
Reviewed
Apr 10, 2026
Published by the National Vulnerability Database
Apr 17, 2026
Last updated
Apr 24, 2026
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue.
References