CVE-2025-52486

Source
https://cve.org/CVERecord?id=CVE-2025-52486
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52486.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-52486
Aliases
Published
2025-06-21T02:42:47.816Z
Modified
2026-04-10T05:30:39.152930Z
Severity
  • 6.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjects
Details

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows specially crafted content in URLs to be used with TokenReplace and not be properly sanitized by some SkinObjects. This issue has been patched in version 10.0.1.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52486.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/dnnsoftware/dnn.platform

Affected ranges

Type
GIT
Repo
https://github.com/dnnsoftware/dnn.platform
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v10.*
v10.0.0
v9.*
v9.1.0
v9.10.0
v9.10.1
v9.10.2
v9.11.0
v9.11.1
v9.12.0
v9.13.0
v9.13.1
v9.13.2
v9.13.3
v9.13.4
v9.13.5
v9.13.6
v9.13.7
v9.13.8
v9.3.0-rc0
v9.3.0-rc1
v9.4.0
v9.4.0-rc0
v9.4.0-rc1
v9.4.1
v9.4.1-rc1
v9.4.2
v9.4.2-rc1
v9.4.3
v9.4.3-rc1
v9.4.4
v9.5.0
v9.5.0-rc2
v9.6.0
v9.6.1
v9.6.2
v9.7.0
v9.7.1
v9.7.2
v9.8.0
v9.8.1
v9.9.0
v9.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52486.json"