Nopcommerce
by Nopsolutions
Source repositories
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-65593 | Hig | 0.57 | 8.8 | 0.00 | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality. | ||
| CVE-2025-65592 | Med | 0.40 | 6.1 | 0.00 | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields are stored in the backend database and executed automatically whenever a user views the… | ||
| CVE-2025-65589 | Med | 0.40 | 6.1 | 0.00 | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality. | ||
| CVE-2024-38963 | Med | 0.40 | 6.1 | 0.00 | Jul 9, 2024 | Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProductReview.ReviewText" parameter(s) (Reviews) when creating a new review. | ||
| CVE-2025-11699 | Hig | 0.39 | 7.1 | 0.00 | Dec 1, 2025 | nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid session cookie access to privileged endpoints (such as /admin) even after the legitimate user has logged out,… | ||
| CVE-2025-65591 | Med | 0.35 | 5.4 | 0.00 | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality. | ||
| CVE-2025-65590 | Med | 0.35 | 5.4 | 0.00 | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Management area. | ||
| CVE-2019-11519 | Med | 0.32 | 4.9 | 0.01 | Apr 25, 2019 | Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen. |
- risk 0.57cvss 8.8epss 0.00
nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.
- risk 0.40cvss 6.1epss 0.00
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields are stored in the backend database and executed automatically whenever a user views the…
- risk 0.40cvss 6.1epss 0.00
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality.
- risk 0.40cvss 6.1epss 0.00
Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProductReview.ReviewText" parameter(s) (Reviews) when creating a new review.
- risk 0.39cvss 7.1epss 0.00
nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid session cookie access to privileged endpoints (such as /admin) even after the legitimate user has logged out,…
- risk 0.35cvss 5.4epss 0.00
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality.
- risk 0.35cvss 5.4epss 0.00
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Management area.
- risk 0.32cvss 4.9epss 0.01
Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen.