Executive brief
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
Affected products
- NuGet DotNetNuke.Core
Junglewise Threat Intelligence
CVE-2025-64094 · Severity: low · CVSS 3.1 · Published 2025-10-29
Technologies: DotNetNuke.Core (NuGet). Vendors: NuGet.
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload