CVE-2025-59535

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. This issue has been patched in version 10.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*

History

29 Sep 2025, 12:53

Type Values Removed Values Added
References () https://github.com/dnnsoftware/Dnn.Platform/blob/develop/DNN%20Platform/Library/UI/Skins/Skin.cs#L305 - () https://github.com/dnnsoftware/Dnn.Platform/blob/develop/DNN%20Platform/Library/UI/Skins/Skin.cs#L305 - Product
References () https://github.com/dnnsoftware/Dnn.Platform/commit/72f30f69fd2214d77f6c2577dfcca495a24caf5c - () https://github.com/dnnsoftware/Dnn.Platform/commit/72f30f69fd2214d77f6c2577dfcca495a24caf5c - Patch
References () https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-wq2j-w9pm-7x2p - () https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-wq2j-w9pm-7x2p - Vendor Advisory
CPE cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*
First Time Dnnsoftware dotnetnuke
Dnnsoftware

22 Sep 2025, 21:22

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-22 21:16

Updated : 2025-09-29 12:53


NVD link : CVE-2025-59535

Mitre link : CVE-2025-59535

CVE.ORG link : CVE-2025-59535


JSON object : View

Products Affected

dnnsoftware

  • dotnetnuke
CWE
CWE-20

Improper Input Validation

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-829

Inclusion of Functionality from Untrusted Control Sphere