---
id: CVE-2025-62802
title: >-
  DNN (formerly DotNetNuke) is an open-source web content management platform
  (CMS) in the Microsoft ecosystem
summary: >-
  DNN (formerly DotNetNuke) is an open-source web content management platform
  (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the out-of-box experience
  for HTML editing allows unauthenticated users to upload files. This opens a
  potentia…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-434
  - CWE-1188
vendor: dnnsoftware
product: dotnetnuke
affected:
  - dotnetnuke < 10.1.1
patched:
  - dotnetnuke 10.1.1
published: '2025-10-28'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62802'
references:
  - url: >-
      https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-2374-6cvw-qmx6
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00233
epssPercentile: 0.12984
ingestedAt: '2026-10-08T11:31:27.665Z'
---

## Overview

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the out-of-box experience for HTML editing allows unauthenticated users to upload files. This opens a potential vector to other security issues and is not needed on most implementations. This vulnerability is fixed in 10.1.1.

## Affected

- `dotnetnuke < 10.1.1`

## Remediation

Upgrade past the affected range:

- `dotnetnuke 10.1.1`
