{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-30T15:42:36.897","vulnerabilities":[{"cve":{"id":"CVE-2026-24836","sourceIdentifier":"security-advisories@github.com","published":"2026-01-28T00:15:50.910","lastModified":"2026-06-17T10:23:40.640","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Versions 9.13.10 and 10.2.0 contain a fix for the issue."},{"lang":"es","value":"DNN (anteriormente DotNetNuke) es una plataforma de gestión de contenido web de código abierto (CMS) en el ecosistema de Microsoft. A partir de la versión 9.0.0 y anterior a las versiones 9.13.10 y 10.2.0, las extensiones podían escribir texto enriquecido en las notas de registro, que pueden incluir scripts que se ejecutarían en la PersonaBar al mostrarse. Las versiones 9.13.10 y 10.2.0 contienen una solución para el problema."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"dnnsoftware","product":"Dnn.Platform","versions":[{"version":">= 9.0.0, < 9.13.10","status":"affected"},{"version":">= 10.0.0, < 10.2.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.0,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-28T21:04:00.728156Z","id":"CVE-2026-24836","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"9.13.10","matchCriteriaId":"702DB18F-9415-4782-97AD-BE8BB66C7D47"},{"vulnerable":true,"criteria":"cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"10.2.0","matchCriteriaId":"183DA3B3-D5F9-4C05-93A3-4B17DE048679"}]}]}],"references":[{"url":"https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-2g5g-hcgh-q3rp","source":"security-advisories@github.com","tags":["Vendor Advisory"]}]}}]}