Dotnetnuke 9.0.x < 9.13.10 / 10.0.x < 10.02.00 Potential XSS vulnerability in modules' header and footer (CVE-2026-24784)

medium Nessus Plugin ID 297830

Version 1.2

Feb 6, 2026, 8:56 AM

  • CVSS metrics ("CVSSv2 score" set to 4.7)
  • CVSS metrics ("CVSSv2 vector" set to "CVSS2#AV:N/AC:L/Au:M/C:P/I:P/A:N")
  • CVSS metrics ("CVSSv3 score" set to 4.8)
  • CVSS metrics ("CVSSv3 vector" set to "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N")

Plugin Feed: 202602060856

Version 1.1

Feb 4, 2026, 8:43 PM

  • New

Plugin Feed: 202602042043

* Changelogs are generally available for changes made after Nov 1, 2022