DNN vendor intelligence
DNN Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting DNN products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 4
- Known exploited vulnerabilities affecting DNN products
- In CISA KEV
- 2
- Records also listed in the official catalog
- Beyond CISA KEV
- 2
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- DNN KEVs with sensor-observed exploitation activity
The catalog gap matters for DNN exposure
Two of the four exploited DNN CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss half of this vendor portfolio.
- 50%
- Covered by CISA
- 50%
- Beyond CISA
- 3
- Product families
Attested DNN CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-52488
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input |
Dnn.Platform | High | Beyond CISA | 12 Sep 2025 |
|
CVE-2025-64095
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite |
Dnn.Platform | High | Beyond CISA | 28 Oct 2025 |
|
CVE-2018-18325
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an... |
DNN Platform | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2018-15811
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. |
DotNetNuke | Confirmed | In CISA | 03 Nov 2021 |
No DNN CVEs match this search or filter.
Showing 4 of 4 DNN known exploited vulnerabilities.
Recurring weakness patterns
Inadequate encryption strength, exposure, and unrestricted upload account for four mapped occurrences across this DNN KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.