VYPR

nopcommerce

by Nopcommerce

Source repositories

CVEs (23)

  • CVE-2019-19682MedDec 9, 2019
    risk 0.31cvss 4.8epss 0.01

    nopCommerce through 4.20 allows XSS in the SaveStoreMappings of the components \Presentation\Nop.Web\Areas\Admin\Controllers\NewsController.cs and \Presentation\Nop.Web\Areas\Admin\Controllers\BlogController.cs via Body or Full to Admin/News/NewsItemEdit/[id]…

  • CVE-2024-58248LowApr 16, 2025
    risk 0.23cvss 3.5epss 0.00

    nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.

  • CVE-2022-28451HigMay 2, 2022
    risk 0.00cvss 7.5epss 0.02

    nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.

Page 2 of 2