Cross-Site Scripting Vulnerability in DNN Platform by DNN Software
CVE-2026-24784
6.8MEDIUM
What is CVE-2026-24784?
The DNN Platform, an open-source web content management system, is susceptible to a Cross-Site Scripting vulnerability allowing malicious content editors to inject harmful scripts into module headers and footers. These scripts can be executed in the browsers of other users, compromising their security. The issue affects versions 9.0.0 through 9.12.0 and is resolved in versions 9.13.10 and 10.2.0. Users are advised to upgrade promptly to protect their web applications.
Affected Version(s)
Dnn.Platform >= 9.0.0, < 9.13.10 < 9.0.0, 9.13.10
Dnn.Platform >= 10.0.0, < 10.2.0 < 10.0.0, 10.2.0
