VYPR

nopcommerce

by Nopcommerce

Source repositories

CVEs (23)

  • CVE-2019-19683CriDec 9, 2019
    risk 0.59cvss 9.1epss 0.02

    RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/ProcessRequest because of Libraries/Nop.Services/Media/RoxyFileman/FileRoxyFilemanService.cs.

  • CVE-2025-65593HigDec 16, 2025
    risk 0.57cvss 8.8epss 0.00

    nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.

  • CVE-2019-19685HigDec 9, 2019
    risk 0.57cvss 8.8epss 0.01

    RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.

  • CVE-2019-19684HigDec 9, 2019
    risk 0.57cvss 8.8epss 0.02

    nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure because it is possible to upload a crafted Facebook Auth plugin.

  • CVE-2022-33077HigOct 19, 2022
    risk 0.49cvss 7.5epss 0.01

    An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.

  • CVE-2025-65592MedDec 16, 2025
    risk 0.40cvss 6.1epss 0.00

    nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields are stored in the backend database and executed automatically whenever a user views the…

  • CVE-2025-65589MedDec 16, 2025
    risk 0.40cvss 6.1epss 0.00

    nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality.

  • CVE-2021-42193MedOct 3, 2025
    risk 0.40cvss 6.1epss 0.00

    nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires.

  • CVE-2024-38963MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProductReview.ReviewText" parameter(s) (Reviews) when creating a new review.

  • CVE-2022-26954MedOct 20, 2022
    risk 0.40cvss 6.1epss 0.01

    Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePassword function, (2) SignInCustomerAsync…

  • CVE-2022-27461MedMay 4, 2022
    risk 0.40cvss 6.1epss 0.01

    In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.

  • CVE-2022-28449MedApr 26, 2022
    risk 0.40cvss 6.1epss 0.01

    nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system.

  • CVE-2021-26916MedFeb 8, 2021
    risk 0.40cvss 6.1epss 0.01

    In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discountcode parameter.

  • CVE-2025-11699HigDec 1, 2025
    risk 0.39cvss 7.1epss 0.00

    nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid session cookie access to privileged endpoints (such as /admin) even after the legitimate user has logged out,…

  • CVE-2025-65591MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality.

  • CVE-2025-65590MedDec 16, 2025
    risk 0.35cvss 5.4epss 0.00

    nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Management area.

  • CVE-2022-28450MedApr 26, 2022
    risk 0.35cvss 5.4epss 0.01

    nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.

  • CVE-2022-28448MedApr 26, 2022
    risk 0.35cvss 5.4epss 0.00

    nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.

  • CVE-2020-29475MedDec 29, 2020
    risk 0.34cvss 4.8epss 0.01

    nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability can allow an attacker to inject the XSS payload in Schedule tasks and each time any user will go to that page of the website, the XSS triggers and attacker can…

  • CVE-2019-11519MedApr 25, 2019
    risk 0.32cvss 4.9epss 0.01

    Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen.

Page 1 of 2