CVE-2015-2794: Dnnsoftware DotNetNuke
Critical severity, CVSS 9.8. EPSS: 75.1% chance of exploitation in the next 30 days.
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
Affected products
- Dnnsoftware DotNetNuke: up to and including 07.04.00
Published 2017-02-06. Last modified 2026-06-17.