Cross-Site Scripting Vulnerability in DNN Platform Prompt Module
CVE-2025-59545

9.1CRITICAL

Key Information:

Vendor
CVE Published:
23 September 2025

What is CVE-2025-59545?

The Prompt module in DNN Platform, an open-source content management system, is susceptible to a Cross-Site Scripting (XSS) vulnerability. This flaw allows attackers to execute arbitrary commands that can return raw HTML. Despite efforts to sanitize input for display in other contexts, malicious scripts can still bypass these measures when handled through specific commands, posing significant security risks to users. The vulnerability has been addressed in version 10.1.0, highlighting the importance of maintaining up-to-date software to protect against potential threats.

Affected Version(s)

Dnn.Platform < 10.1.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59545 : Cross-Site Scripting Vulnerability in DNN Platform Prompt Module