CVE-2026-24836Disclosure(dnnsoftware / dotnetnuke)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Versions 9.13.10 and 10.2.0 contain a fix for the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dotnetnuke

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
dotnetnuke

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-28: 2Mentions · 2026-02-02: 1Technical Details · 2026-01-28: 101-2802-02
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-282
Disclosure1General1
2026-02-021
Disclosure1
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-24836 (CVSS:7.6, HIGH) is Undergoing Analysis. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting i..https://nvd.nist.gov/vuln/detail/CVE-2026-24836 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces that CVE-2026‑24836, a high‑severity flaw in DNN, is currently being analyzed; it offers no PoC, exploit, active‑exploitation evidence, or mitigation information.

    0000043
    171 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-24836: Trust Issues in the Scheduler: Deep Dive into CVE-2026-24836 A Stored Cross-Site Scripting (XSS) vulnerability in the DNN Platform's Scheduler allows malicious tasks to embed scripts in execution logs. These logs are subsequently rende... https://cvereports.com/reports/CVE-2026-24836

    Post summary

    The report discloses a stored XSS flaw in DNN’s Scheduler that permits injection of malicious scripts into execution logs, but offers no PoC, exploit code, or remediation details.

    0000037
    29 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24836 DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 … https://www.cve.org/CVERecord?id=CVE-2026-24836

    Post summary

    The text only identifies CVE-2026-24836 for DNN without further details.

    00000370
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdnnsoftwaredotnetnuke---

Explore more