Medium severity5.4OSV Advisory· Published Dec 16, 2025· Updated Jun 17, 2026
CVE-2025-65591
CVE-2025-65591
Description
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: release-1.70, release-1.80, release-1.90, …
=4.90.0+ 1 more
- (no CPE)range: =4.90.0
- cpe:2.3:a:nopcommerce:nopcommerce:4.90.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- seclists.org/fulldisclosure/2025/Dec/18nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2025/Dec/18nvdMailing ListThird Party Advisory
- www.nopcommerce.comnvdProduct
News mentions
0No linked articles in our index yet.