← console
voxell vciy

CVE-2025-59545: DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module

ROUTINE

Telemetry drift only. No threshold crossed and no authority ruling changed.

CVE record loaded 2026-09-20.

What to do now held facts and links

  1. Upgrade to dotnetnuke 10.1.0 or later upper bounds of the CVE record's affected ranges
  2. Later advisories still cover the fixes above and name higher ones: DotNetNuke.Core 10.1.1 (CVE-2025-64094), 10.2.0 (CVE-2026-24784), 10.02.0 (CVE-2026-24836), 10.2.0 (CVE-2026-24837), 10.2.0 (CVE-2026-24838), 10.2.2 (CVE-2026-40305), 10.2.2 (CVE-2026-40306), 10.2.2 (CVE-2026-40321) OSV advisories
  3. Record your decision, dated and frozen with today's evidence: patch by a date · mitigated by a compensating control · deferred · accepted the risk · not affected
  4. Check your version against the ranges this record publishes.

What it is stated by the CNA

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). This issue has been patched in version 10.1.0.

weakness
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
affected
dnnsoftware Dnn.Platform
versions
dnnsoftware Dnn.Platform < 10.1.0
published ranges
dnnsoftware dotnetnuke < 10.1.0
first unaffected version, by branch
dotnetnuke 10.1.0
fixed by package (from OSV advisories)
DotNetNuke.Core (NuGet): 10.1.0 GHSA-2qxc-mf4x-wr29
later fixes (from OSV advisories)
DotNetNuke.Core 10.1.0 is inside a range CVE-2025-64094 (GHSA-hmvq-8p83-cq52) lists as affected. That advisory is fixed in 10.1.1.DotNetNuke.Core 10.1.0 is inside a range CVE-2026-24784 (GHSA-jjwg-4948-6wxp) lists as affected. That advisory is fixed in 10.2.0.DotNetNuke.Core 10.1.0 is inside a range CVE-2026-24836 (GHSA-2g5g-hcgh-q3rp) lists as affected. That advisory is fixed in 10.02.0.DotNetNuke.Core 10.1.0 is inside a range CVE-2026-24837 (GHSA-vm5q-8qww-h238) lists as affected. That advisory is fixed in 10.2.0.DotNetNuke.Core 10.1.0 is inside a range CVE-2026-24838 (GHSA-w9pf-h6m6-v89h) lists as affected. That advisory is fixed in 10.2.0.DotNetNuke.Core 10.1.0 is inside a range CVE-2026-40305 (GHSA-fpj4-9qhx-5m6m) lists as affected. That advisory is fixed in 10.2.2.
severity
9.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
assigned by
GitHub_M
published
2025-09-23

check us github.com

Exploit code held, dated

exploit code
None held in the PoC-in-GitHub feed. A public repository changes this brief.

What moved held, dated

dateEPSSevent
24 Sep 20250.00047
29 Sep 20250.00048
30 Sep 20250.00049
25 Oct 20250.00057
15 Jun 20260.00499scoring model v2026.06.15
19 Jun 20260.0051
4 Aug 20260.00506
28 Aug 20260.00486

17 observations held. A step marked with a scoring model moved because the measurement was replaced, not because the vulnerability changed.

Outside the record researched, cited

This section reads the record's references and adds cited findings from outside it. It needs an account. Everything above is held facts and is complete without it.

Sign in to add the researched section

What would change this brief held, dated

CISA KEV
Not listed in the catalogue we hold. A listing changes this brief.
exploit probability
0.00 on 2026-08-28 (FIRST's EPSS, a probability and not evidence of exploitation). Next band line: 10% (0.10). Crossing a line changes this brief.
fix
Held: dotnetnuke 10.1.0 (CVE record, loaded 2026-09-20). A newer fix from the CNA or OSV changes this brief.

Watch this CVE What counts as a move

How to check this

Every value above is held with two dates: when it was true upstream (as_of) and when we recorded it (tx_from). Re-derive the exploit probability as it stood on any date:

SELECT value, source, source_version, as_of, tx_from
FROM volatile_valid_as_of('CVE-2025-59545', '2026-10-03T23:59:59.999999Z', now());

Identity above is quoted from the CVE Program record, corpus cvelistv5_20260920, recorded 30 Sep 2026.