Review the complete synchronized DNN advisory catalog, the latest 2026 GHSA/CVE entries, and how DNN Defender converts advisory intelligence into layered prevention and persistence control.
Not rated yet
DNN Defender 03.03.00 does not protect only CVE-2026-40321. Its release knowledge base contains
all 47 official DNN Platform advisories synchronized through 25 August 2026. Security Risk Analysis
compares the running DNN build with the authoritative affected range for every entry, avoids the
false “predates the fix” result on newer versions, and shows the control state beside the exposure.
The authoritative upstream index is the
DNN Platform Security Advisories page.
The packaged catalog is used locally at runtime; customer requests and site details are not sent
to GitHub for this comparison.
Latest official DNN advisories
The most recent upstream release group was published on 25 August 2026. These entries had GHSA
identifiers at synchronization time; a CVE may be assigned later without changing the underlying
Defender coverage mapping.
The same release group also includes private Journal interaction, restricted-file metadata,
profile-picture privacy, and optional HTML-module JavaScript restriction advisories. Security Risk
Analysis displays all of them, not only the highest-severity subset shown above.
Latest CVE-assigned DNN entries
Complete 47-advisory coverage matrix (release snapshot)
This is the packaged knowledge snapshot synchronized through 25 August 2026, not a live claim
about advisories published after that date. “Targeted” means a mapped request path or exploit
pattern has a dedicated Advisory Shield control; “Partial” means a documented subset is guarded;
“No targeted control” means only general layers may apply and must not be presented as a
virtual patch. These are catalog mappings, not proof that a request was blocked on a particular
site. The Security Risk Analysis page shows the running version, affected range, current control
mode, and event evidence. Install the vendor fix for the actual platform repair.
| Advisory |
Severity |
Issue |
Affected range |
Fixed in |
Dedicated control |
| GHSA-g8w5-h3rm-g8rj |
High |
Authorization bypass in image processor |
<10.3.3 |
10.3.3 |
Targeted |
| GHSA-mjq6-87j6-5f4g |
Medium |
Optional JavaScript restrictions for HTML module content |
<10.3.3 |
10.3.3 |
Partial |
| GHSA-hxc3-xv8x-w2g3 |
High |
Portal administrator remote code execution |
<10.3.3 |
10.3.3 |
Targeted |
| GHSA-fpr5-67pq-3hf5 |
Critical |
User registration approval authorization bypass |
<10.3.3 |
10.3.3 |
Targeted |
| GHSA-r4c4-vmqp-vxf2 |
Medium |
Unauthorized likes on private journal posts |
<10.3.3 |
10.3.3 |
Targeted |
| GHSA-56m6-r25g-78x6 |
High |
Content approval workflow bypass |
<10.3.3 |
10.3.3 |
Targeted |
| GHSA-4q79-2m2q-gw8w |
Medium |
GroupEdit postback tampering lets one group owner update another group |
<10.3.3 |
10.3.3 |
Targeted |
| GHSA-hqgc-qj63-mx24 |
Medium |
Permission precedence flaw in module permissions |
<10.3.3 |
10.3.3 |
Targeted |
| GHSA-hmwm-c2hx-wmxh |
Medium |
Server-Side request forgery in journal module |
<10.3.3 |
10.3.3 |
Targeted |
| GHSA-74j7-h73j-qmc9 |
Medium |
Unauthorized file metadata disclosure in restricted folders |
<10.3.3 |
10.3.3 |
Targeted |
| GHSA-38xj-rgg3-5cjj |
High |
Stored XSS potentially leading to host privilege escalation |
<13.3.3 |
13.3.3 |
Partial |
| GHSA-86mr-4mmw-j9g2 |
Medium |
Unauthorized comments on private journal posts |
>6.0.0 |
10.3.3 |
Targeted |
| GHSA-6c87-vxw3-jr98 |
Medium |
Private message attachment authorization bypass |
9.13.7 |
10.3.3 |
Targeted |
| GHSA-73p4-7q5m-r5wc |
Medium |
Journal private files authorization bypass |
<10.3.3 |
10.3.3 |
Targeted |
| GHSA-vrq9-6m4c-5prp |
Medium |
Profile pictures can be viewed by any visitor |
<10.3.3 |
Check advisory |
Targeted |
| GHSA-fcpv-w245-r2q7 |
Low |
Security code analysis rules triggered |
>6.0.0 |
10.2.2 |
No targeted control |
| GHSA-ffq7-898w-9jc4 |
High |
Stored cross-site-scripting (XSS) via SVG upload |
<10.2.2 |
10.2.2 |
Targeted |
| GHSA-2rhw-gw3f-477j |
Low |
Same HostGUID for all new installs |
> 10.0.0 |
10.2.2 |
No targeted control |
| GHSA-fpj4-9qhx-5m6m |
Medium |
Force Friend Request Acceptance |
>=6.0.0 |
10.2.2 |
Targeted |
| GHSA-w9pf-h6m6-v89h |
Critical |
Stored XSS via Module Title |
<9.13.10; >=10.0.0,<10.2.0 |
9.13.10, 10.02.00 |
Partial |
| GHSA-vm5q-8qww-h238 |
High |
Stored XSS in Module Deletion Confirmation Modal |
>=10.0.0,<10.2.0; >=9.0.0,<=9.13.9 |
9.13.10, 10.2.0 |
Partial |
| GHSA-2g5g-hcgh-q3rp |
High |
Stored XSS in Scheduler LogNotes |
>=10.0.0,<10.2.0; >=9.0.0,<=9.13.9 |
9.13.10, 10.02.00 |
Partial |
| GHSA-9r3h-mpf8-25gj |
High |
Stored XSS in Module Description |
<9.13.10; >=10.0.0,<10.2.0 |
9.13.10, 10.02.00 |
Partial |
| GHSA-jjwg-4948-6wxp |
Medium |
Potential XSS vulnerability in modules' header and footer |
>=10.0.0,<10.2.0; >=9.0.0,<=9.13.9 |
9.13.10, 10.02.00 |
Partial |
| GHSA-3m8r-w7xg-jqvw |
Critical |
Insufficient Access Control - Image Upload allows for Site Content Overwrite |
<10.1.1 |
10.1.1 |
Partial |
| GHSA-hmvq-8p83-cq52 |
Medium |
Stored cross-site-scripting (XSS) via SVG upload |
<10.1.1 |
10.1.1 |
Targeted |
| GHSA-2374-6cvw-qmx6 |
Medium |
CKEditor Provider allows unauthenticated upload out-of-the-box |
<10.1.1 |
10.1.1 |
Targeted |
| GHSA-jc4g-c8ww-5738 |
Medium |
Reflected Cross-Site Scripting (XSS) using url to profile |
<10.1.0 |
10.1.0 |
Targeted |
| GHSA-5fj9-542v-w4rq |
Medium |
Reflected Cross-Site Scripting (XSS) in CKEditor File Browser |
<10.1.0 |
10.1.0 |
No targeted control |
| GHSA-cgqj-mw4m-v7hp |
Medium |
Vulnerability in CKEditor's File Uploader functionality through Unicode obfuscation |
<10.1.0 |
10.1.0 |
Targeted |
| GHSA-gj8m-5492-q98h |
Low |
Stored XSS Using Backend Admin Credentials |
<10.1.0 |
10.1.0 |
Partial |
| GHSA-2qxc-mf4x-wr29 |
Critical |
Stored Cross-Site Scripting (XSS) in Prompt module |
<10.1.0 |
10.1.0 |
Partial |
| GHSA-7rcc-q6rq-jpcm |
Medium |
Stored Cross-Site Scripting (XSS) in Profile Biography field |
<10.1.0 |
10.1.0 |
Partial |
| GHSA-wq2j-w9pm-7x2p |
Medium |
Loading unused themes on annonymous clients through query parameters |
<10.1.0 |
10.1.0 |
Targeted |
| GHSA-mgfv-2362-jq96 |
High |
NTLM hash leakage via SMB Share Interaction with malicious user input |
>6.0.0 |
10.0.1 |
Targeted |
| GHSA-fjhg-3mrh-mm7h |
High |
Possibly bypass of IP Filters |
>7.0.0 |
10.0.1 |
Partial |
| GHSA-pf4h-vrv6-cmvr |
Medium |
Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjects |
>6.0.0 |
10.0.1 |
Targeted |
| GHSA-wwc9-wmm3-2pmf |
Medium |
Stored Cross-Site Scripting (XSS) in Activity Feed |
>6.0.0 |
10.0.1 |
Partial |
| GHSA-m4hf-fxcg-cp34 |
Medium |
Stored Cross-Site Scripting (XSS) possible with svg files rendered inline |
<9.13.9 |
9.13.9 |
Targeted |
| GHSA-79m3-rvx2-3qq9 |
Medium |
Reflected Cross-Site Scripting (XSS) in module actions in edit mode |
<9.13.9 |
9.13.9 |
Targeted |
| GHSA-62mf-vhhw-xmf8 |
Low |
Site Import could use an external source with a crafted request |
<9.13.9 |
9.13.9 |
Targeted |
| GHSA-vc6j-mcqj-rgfp |
Medium |
Possible Denial of Service (DoS) in DNN.PLATFORM registration |
<9.13.8 |
9.13.8 |
Partial |
| GHSA-vxcm-4rwh-chpc |
Medium |
A registered user may enumerate and access files they should not have access to |
<9.13.8 |
9.13.8 |
Targeted |
| GHSA-3f7v-qx94-666m |
Medium |
Server-Side Request Forgery (SSRF) in DotNetNuke.Core |
<9.13.8 |
9.13.8 |
Partial |
| GHSA-2rrc-g594-rhqw |
Medium |
Unexpected external content may be displayed in ImageHandler |
<9.13.4 |
9.13.4 |
No targeted control |
| GHSA-48q9-3p26-8595 |
Medium |
The possibility of bypassing Captcha |
<9.13.8 |
9.13.8 |
No targeted control |
| GHSA-8q89-mqw7-9pp7 |
Low |
File contents aren't checked when uploading files |
<9.13.2 |
9.13.2 |
Partial |
What each coverage layer can establish
| Stage |
DNN Defender action |
| Exposure intelligence |
Evaluates every synchronized official advisory against the running DNN version and links to the authoritative record |
| Targeted virtual patch |
Advisory Shield Strict denies a documented, mapped exploit route or behavior when that control is active; a partial control covers only the paths stated in its advisory row |
| Behavioral request defense |
The normalized WAF scores route, verb, role, input, upload, destination, rate, and DNN ownership signals even before a CVE-specific rule exists |
| Payload detection |
Rules, structural AST/IL analysis, and AI inspect modern .NET/ASP.NET web-shell behavior instead of trusting filename or extension |
| Persistence control |
Realtime Monitor, quarantine, and FIM expose executable additions or changes and preserve evidence for containment |
| Continuous response |
New honeypot and incident evidence can become a bounded rule, structural pattern, knowledge mapping, or model update in a signed release |
Publication statement: DNN Defender assesses all advisories in the catalog synchronized
through 25 August 2026. In 03.03.00, 42 map to targeted or partial controls; five have no
dedicated virtual patch. A finding shows exposure, current control mode, and the actual observed
or blocked outcome separately. Strict and Prevention deny a request only when a mapped control
matches. A vendor-fixed DNN release remains the definitive correction for vulnerable core code.
CVE-2026-40321 is one example, not the boundary
For CVE-2026-40321, Security Risk Analysis identifies DNN <10.2.2 as affected. When the
relevant controls are enabled in blocking mode and a mapped request matches, Advisory Shield
Strict and WAF-UPLOAD-001 can deny SVG/SVGZ uploads at the HTTP request boundary and record
the evidence. The same control architecture is also applied to authorization bypass, workflow, SSRF,
private-file, remote-source, executable upload, XSS, forwarding-header, and other advisory
families listed in the catalog.
Security boundary
“Covered” does not mean DNN core binaries have been rewritten. A targeted control blocks the known
route/pattern; a partial control closes important exploit paths; the scanner and FIM address
payload and persistence behavior. Direct disk access, memory-only/native malware, an unknown
custom route, or content stored before protection was enabled may require additional investigation.
Verify Advisory Shield = Enabled + Strict, WAF = Prevention, Realtime Monitor health, a valid
FIM baseline, and successful scheduled scans. Keep DNN Defender after upgrading, because future
advisories, extension vulnerabilities, credentials, unsafe uploads, and configuration errors remain
relevant. The vendor-fixed DNN release remains the definitive correction for vulnerable core code.