CVE-2013-3943: Dnnsoftware DotNetNuke
Low severity, CVSS 3.5. EPSS: 0.9% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Display Name field in the Manage Profile.
Affected products
- Dnnsoftware DotNetNuke: up to and including 6.2.8; version 1.0.6 only; version 1.0.7 only; version 1.0.8 only; version 1.0.9 only; version 1.0.10d only; …
Published 2014-03-12. Last modified 2026-06-16.