{"id":"CVE-2025-59535","aliases":["GHSA-wq2j-w9pm-7x2p"],"url":"https://o3.security/vulnerability/CVE-2025-59535","summary":"DotNetNuke.Core allows loading of unused themes on anonymous clients through query parameters","details":"DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. This issue has been patched in version 10.1.0.","published":"2025-09-22T20:59:03.801Z","modified":"2026-08-12T03:51:24.090325600Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},"epss":{"score":0.00322,"percentile":0.25039,"asOf":"2026-08-18"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"DotNetNuke.Core","fixedVersion":"10.1.0"}],"fix":{"url":"https://github.com/dnnsoftware/Dnn.Platform/commit/72f30f69fd2214d77f6c2577dfcca495a24caf5c","label":"dnnsoftware/Dnn.Platform@72f30f6"},"references":[{"type":"WEB","url":"https://github.com/dnnsoftware/Dnn.Platform/blob/develop/DNN%20Platform/Library/UI/Skins/Skin.cs#L305"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59535.json"},{"type":"ADVISORY","url":"https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-wq2j-w9pm-7x2p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59535"},{"type":"FIX","url":"https://github.com/dnnsoftware/Dnn.Platform/commit/72f30f69fd2214d77f6c2577dfcca495a24caf5c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:24.090325600Z"}}