Medium severity6.1NVD Advisory· Published Feb 8, 2021· Updated Jun 17, 2026
CVE-2021-26916
CVE-2021-26916
Description
In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discountcode parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:nopcommerce:nopcommerce:4.30:-:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:nopcommerce:nopcommerce:4.30:-:*:*:*:*:*:*
- (no CPE)range: 4.30
- nopCommerce/nopCommercedescription
Patches
Vulnerability mechanics
References
1- github.com/nopSolutions/nopCommerce/issues/5322nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.