NuGet package intelligence
DotNetNuke.Core Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the NuGet package DotNetNuke.Core, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 3
- Known exploited vulnerabilities affecting DotNetNuke.Core
- In CISA KEV
- 3
- Records also listed in the official catalog
- Beyond CISA KEV
- 0
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 1
- DotNetNuke.Core KEV with sensor-observed exploitation activity
Review DotNetNuke.Core exploitation against the versions you run
All three exploited DotNetNuke.Core vulnerabilities tracked here are also listed in CISA KEV.
- 100%
- Covered by CISA
- 0%
- Beyond CISA
Attested DotNetNuke.Core vulnerabilities
3 known exploited vulnerabilities affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2017-9822
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites." |
In CISA | 03 Nov 2021 |
|
CVE-2018-18325
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an... |
In CISA | 03 Nov 2021 |
|
CVE-2018-15811
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. |
In CISA | 03 Nov 2021 |
Recurring weakness patterns
Inadequate Encryption Strength and Improper Control of Generation of Code ('Code Injection') account for mapped occurrences across this DotNetNuke.Core KEV portfolio.