Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Display Name field in the Manage Profile.
Metrics
Affected Vendors & Products
References
History
Fri, 24 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dnnsoftware
Dnnsoftware dotnetnuke |
|
| CPEs | cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.10d:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.10e:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.6:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.7:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.8:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:1.0.9:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:2.1.1:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:2.1.2:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:3.0.11:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:3.0.7:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:3.0.8:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:3.1.0:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:3.3.5:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.0:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.3.5:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.4.1:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.5.2:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.5.4:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.5.5:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.6.0:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.6.1:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.6.2:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.7.0:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.8.0:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.8.1:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.8.2:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.8.3:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.8.4:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.9.1:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.9.2:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:4.9:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:5.05.01:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:5.06.00:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:5.0:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:5.1.1:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:5.1.2:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:5.1.3:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:5.1.4:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:5.1:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.0.0:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.0.1:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.0.2:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.1.0:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.1.1:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.1.2:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.1.3:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.1.4:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.1.5:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.2.0:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.2.1:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.2.2:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.2.3:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.2.4:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.2.5:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.2.6:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:6.2.7:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:7.0.0:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:7.0.1:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:7.0.3:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:7.0.4:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:7.0.5:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:7.0.6:*:*:*:*:*:*:* cpe:2.3:a:dotnetnuke:dotnetnuke:7.1.0:*:*:*:*:*:*:* |
cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:1.0.10d:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:1.0.10e:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:1.0.6:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:1.0.7:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:1.0.8:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:1.0.9:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:2.1.1:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:2.1.2:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:3.0.11:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:3.0.7:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:3.0.8:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:3.1.0:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:3.3.5:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.0:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.3.5:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.4.1:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.5.2:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.5.4:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.5.5:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.6.0:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.6.1:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.6.2:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.7.0:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.8.0:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.8.1:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.8.2:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.8.3:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.8.4:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.9.1:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.9.2:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:4.9:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:5.05.01:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:5.06.00:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:5.0:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:5.1.1:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:5.1.2:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:5.1.3:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:5.1.4:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:5.1:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.0.0:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.0.1:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.0.2:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.1.0:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.1.1:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.1.2:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.1.3:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.1.4:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.1.5:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.2.0:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.2.1:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.2.2:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.2.3:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.2.4:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.2.5:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.2.6:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:6.2.7:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:7.0.0:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:7.0.1:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:7.0.3:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:7.0.4:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:7.0.5:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:7.0.6:*:*:*:*:*:*:* cpe:2.3:a:dnnsoftware:dotnetnuke:7.1.0:*:*:*:*:*:*:* |
| Vendors & Products |
Dotnetnuke
Dotnetnuke dotnetnuke |
Dnnsoftware
Dnnsoftware dotnetnuke |
Status: PUBLISHED
Assigner: flexera
Published: 2014-03-12T14:00:00.000Z
Updated: 2024-08-06T16:30:49.078Z
Reserved: 2013-06-04T00:00:00.000Z
Link: CVE-2013-3943
No data.
Status : Deferred
Published: 2014-03-12T14:55:30.647
Modified: 2026-04-24T17:34:37.240
Link: CVE-2013-3943
No data.