CVE-2025-62802: DNN CKEditor Provider allows unauthenticated upload out-of-the-box
The out-of-box experience for HTML editing allows unauthenticated users to upload files. This opens a potential vector to other security issues and is not needed on most implementations.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-62802 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →