Cross-site scripting in DotNetNuke - #VU146085
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in the victim\'s browser.
The vulnerability exists due to cross-site scripting (XSS) in the HTML module when storing HTML content with embedded JavaScript. A remote user can submit crafted HTML module content to execute arbitrary JavaScript in the victim\'s browser.
This issue affects environments where content editing permissions are granted to users who are not fully trusted.