Advisory Database
  • Advisories
  • Dependency Scanning
  1. nuget
  2. ›
  3. DotNetNuke.Core
  4. ›
  5. CVE-2025-59545

CVE-2025-59545: DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module

September 23, 2025

The Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS).

References

  • github.com/advisories/GHSA-2qxc-mf4x-wr29
  • github.com/dnnsoftware/Dnn.Platform
  • github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-2qxc-mf4x-wr29
  • nvd.nist.gov/vuln/detail/CVE-2025-59545

Code Behaviors & Features

Detect and mitigate CVE-2025-59545 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 10.1.0

Fixed versions

  • 10.1.0

Solution

Upgrade to version 10.1.0 or above.

Impact 9 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

nuget/DotNetNuke.Core/CVE-2025-59545.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 07 Oct 2025 00:18:18 +0000.