logo

How to find DNN Software installations on your network

ID: d540ecc8-3bea-5457-83b1-291543a0dc62

STIX ID: report--d540ecc8-3bea-5457-83b1-291543a0dc62

Feed Name: runZero Blog

Threat Score
70/100

Date Published: 2025-10-31

Date Updated: 2026-04-29

Author: Matthew Kienow

...
...

DNN Software disclosed three vulnerabilities affecting DNN versions prior to 10.1.1: a critical unauthenticated unrestricted file upload (CVE-2025-64095, CVSS 10.0) that can overwrite site files and enable chained attacks, a stored XSS via SVG uploads (CVE-2025-64094, CVSS 6.4), and an unrestricted CKEditor file upload issue (CVE-2025-62802, CVSS 4.3); users are advised to upgrade to DNN 10.1.1 or later and a runZero query is provided to locate potentially vulnerable systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.