How to find DNN Software installations on your network
ID: d540ecc8-3bea-5457-83b1-291543a0dc62
STIX ID: report--d540ecc8-3bea-5457-83b1-291543a0dc62
Feed Name: runZero Blog
Threat Score
DNN Software disclosed three vulnerabilities affecting DNN versions prior to 10.1.1: a critical unauthenticated unrestricted file upload (CVE-2025-64095, CVSS 10.0) that can overwrite site files and enable chained attacks, a stored XSS via SVG uploads (CVE-2025-64094, CVSS 6.4), and an unrestricted CKEditor file upload issue (CVE-2025-62802, CVSS 4.3); users are advised to upgrade to DNN 10.1.1 or later and a runZero query is provided to locate potentially vulnerable systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
