A critical vulnerability, CVE-2025-64095, has been identified in the DNN Platform, an open-source CMS widely used in the Microsoft ecosystem. The flaw, rated CVSS 10.0, allows unauthenticated attackers to upload files via the default HTML editor provider, enabling them to overwrite existing files on the server. This can result in complete compromise of website confidentiality, integrity, and availability, including defacement and the potential for further attacks such as stored XSS, session hijacking, and credential theft. All versions prior to 10.1.1 are affected, and administrators are strongly urged to update to version 10.1.1 immediately.
The vulnerability is notable for its ease of exploitation, requiring no authentication or privileges. Security advisories recommend that site owners review file logs for unauthorized uploads or modifications if running unpatched versions. The DNN Platform team has released a patch, and immediate action is advised to mitigate the risk of exploitation and potential website compromise.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A ProjectDiscovery Nuclei template pull request was opened to detect CVE-2025-64095 as an unrestricted arbitrary file upload issue in DNN. This added public technical detection content for identifying vulnerable installations.
Public reporting said the issue affects all DNN Platform versions prior to 10.1.1 and can lead to full website compromise, defacement, and stored XSS. Administrators were urged to upgrade immediately to version 10.1.1 and review logs for suspicious uploads or file modifications.
A critical vulnerability, CVE-2025-64095, was disclosed in DNN Platform. The flaw involves insufficient access control in the default HTML editor provider, enabling unauthenticated file upload and overwrite of existing site content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcerunzero.com
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.