Script Injection Vulnerability in DNN Web Content Management Platform
CVE-2026-24837
7.7HIGH
What is CVE-2026-24837?
The DNN Platform, an open-source web content management system, has a vulnerability wherein malicious scripts can be injected through module friendly names. This issue affects versions 9.0.0 to 9.13.9 and 10.0.0 to 10.1.9, potentially allowing unintended script execution during module operations in the Persona Bar. Updates in versions 9.13.10 and 10.2.0 address this issue, enhancing security by preventing the execution of such scripts.
Affected Version(s)
Dnn.Platform >= 9.0.0, < 9.13.10 < 9.0.0, 9.13.10
Dnn.Platform >= 10.0.0, < 10.2.0 < 10.0.0, 10.2.0
