CVE-2026-40321Disclosure(dnnsoftware / dotnetnuke)

LOWCVSS 8.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dnnsoftware dotnetnuke systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-87

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dotnetnuke

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-17); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
dotnetnuke

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-04-30: 1Patch / Workaround · 2026-04-18: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-18: 1Technical Details · 2026-04-30: 104-1704-1804-30
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40321 DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially… https://www.cve.org/CVERecord?id=CVE-2026-40321

    Post summary

    CVE-2026-40321 affects DNN before version 10.2.2, allowing a user to upload a specially crafted file; upgrading to 10.2.2 mitigates the issue.

    00010178
    57.2K followersView on X
  • Neural Newscast@NeuralNewscast
    Disclosure

    In this episode of Prime Cyber Insights, we break down a series of high-impact vulnerabilities and breaches that signal a changing of the guard in cybersecurity defense and offense. We lead with the disclosure of CVE-2026-40321, a critical cross-site scripting flaw in the https://t.co/9ANap5Whkt

    Post summary

    The tweet discloses CVE-2026-40321, a critical cross‑site scripting vulnerability, and links to further details without providing exploitation or mitigation information.

    0000017
    37 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-40321 DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to … CVSS 8.0 Full analysis → https://sec.kaitan.id/cves/CVE-2026-40321 #Microsoft #CyberSecurity #InfoSec

    Post summary

    The post announces a high‑severity vulnerability (CVE‑2026‑40321) in DNN/DotNetNuke with a CVSS score of 8.0 and links to a full analysis, offering no PoC, exploit, or patch information.

    000004
    145 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdnnsoftwaredotnetnuke---

Explore more