Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-ffq7-898w-9jc4 | DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload |
Fri, 24 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dnnsoftware dotnetnuke
|
|
| CPEs | cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dnnsoftware dotnetnuke
|
Mon, 20 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Apr 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dnnsoftware
Dnnsoftware dnn Platform |
|
| Vendors & Products |
Dnnsoftware
Dnnsoftware dnn Platform |
Fri, 17 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. | |
| Title | DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload | |
| Weaknesses | CWE-87 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-22T03:55:44.141Z
Reserved: 2026-04-10T21:41:54.505Z
Link: CVE-2026-40321
Updated: 2026-04-20T16:00:52.230Z
Status : Analyzed
Published: 2026-04-17T22:16:32.653
Modified: 2026-04-24T14:41:30.220
Link: CVE-2026-40321
No data.
OpenCVE Enrichment
Updated: 2026-04-18T09:00:05Z
Github GHSA