Code Injection in DotNetNuke - #VU146086
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper control of code generation in the theme management functionality when incorporating administrator-supplied content into server-side resources. A remote privileged user can supply crafted content to execute arbitrary code.
Under certain deployment configurations, exploitation can compromise other portals hosted on the same instance.