---
id: CVE-2025-64094
title: >-
  DNN (formerly DotNetNuke) is an open-source web content management platform
  (CMS) in the Microsoft ecosystem
summary: >-
  DNN (formerly DotNetNuke) is an open-source web content management platform
  (CMS) in the Microsoft ecosystem. Prior to 10.1.1,  sanitization of the
  content of uploaded SVG files was not covering all possible XSS scenarios.
  This vulnerabi…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: dnnsoftware
product: dotnetnuke
affected:
  - dotnetnuke < 10.1.1
patched:
  - dotnetnuke 10.1.1
published: '2025-10-28'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64094'
references:
  - url: >-
      https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-hmvq-8p83-cq52
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00195
epssPercentile: 0.08397
ingestedAt: '2026-10-08T11:31:27.666Z'
---

## Overview

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1,  sanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. This vulnerability exists because of an incomplete fix for CVE-2025-48378. This vulnerability is fixed in 10.1.1.

## Affected

- `dotnetnuke < 10.1.1`

## Remediation

Upgrade past the affected range:

- `dotnetnuke 10.1.1`
