CVE-2018-9126: Zldnn Dnnarticle

Critical severity, CVSS 9.8. EPSS: 48.9% chance of exploitation in the next 30 days.

The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credentials, via the /GetCSS.ashx/?CP=%2fweb.config URI.

Affected products

  • Zldnn Dnnarticle: version 11 only

Published 2018-04-04. Last modified 2026-06-17.