CVE-2025-65593
- EPSS 0.03%
- Veröffentlicht 16.12.2025 00:00:00
- Zuletzt bearbeitet 19.12.2025 16:38:29
nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.
CVE-2025-65592
- EPSS 0.04%
- Veröffentlicht 16.12.2025 00:00:00
- Zuletzt bearbeitet 19.12.2025 16:40:13
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields are stored in the backend database and executed automatically w...
CVE-2025-65591
- EPSS 0.04%
- Veröffentlicht 16.12.2025 00:00:00
- Zuletzt bearbeitet 19.12.2025 16:41:52
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality.
CVE-2025-65590
- EPSS 0.04%
- Veröffentlicht 16.12.2025 00:00:00
- Zuletzt bearbeitet 19.12.2025 16:42:56
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Management area.
CVE-2025-65589
- EPSS 0.04%
- Veröffentlicht 16.12.2025 00:00:00
- Zuletzt bearbeitet 19.12.2025 16:43:38
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality.
CVE-2025-11699
- EPSS 0.04%
- Veröffentlicht 01.12.2025 15:17:57
- Zuletzt bearbeitet 19.12.2025 17:02:39
nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid session cookie access to privileged endpoints (such as /admin) even after the legitimat...
CVE-2021-42193
- EPSS 0.03%
- Veröffentlicht 03.10.2025 00:00:00
- Zuletzt bearbeitet 19.12.2025 17:07:54
nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires.
CVE-2024-58248
- EPSS 0.14%
- Veröffentlicht 16.04.2025 00:00:00
- Zuletzt bearbeitet 19.12.2025 17:14:34
nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.
CVE-2024-38963
- EPSS 1.15%
- Veröffentlicht 09.07.2024 22:15:02
- Zuletzt bearbeitet 31.12.2025 01:58:58
Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProductReview.ReviewText" parameter(s) (Reviews) when creating a new review.
CVE-2022-26954
- EPSS 0.28%
- Veröffentlicht 20.10.2022 11:15:10
- Zuletzt bearbeitet 08.05.2025 18:15:40
Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePassword functi...