CVE-2020-37103: Dnnsoftware DotNetNuke
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML files with executable scripts through journal tools. Attackers can upload XML files with XHTML namespace scripts to execute arbitrary JavaScript in users' browsers, potentially bypassing CSRF protections and performing more damaging attacks.
Affected products
- Dnnsoftware DotNetNuke: up to and including 9.5.0
Published 2026-02-03. Last modified 2026-06-17.