Junglewise Threat Intelligence

CVE-2025-64094: DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload

CVE-2025-64094 · Severity: low · CVSS 3.1 · Published 2025-10-29

Technologies: DotNetNuke.Core (NuGet). Vendors: NuGet.

Executive brief

DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload

Affected products

  • NuGet DotNetNuke.Core

Related threats