📦 Nopcommerce

by Nopcommerce

🔍 What is Nopcommerce?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-65593

HIGH CVSS 8.8 Dec 16, 2025

nopCommerce 4.90.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in its Schedule Tasks functionality. This allows attackers to trick authenticated administrators into performing unauthori...

CVE-2025-11699

HIGH CVSS 7.1 Dec 1, 2025

nopCommerce versions 4.70 and prior, and specifically version 4.80.3, fail to properly invalidate session cookies after logout or session termination. This allows attackers with a valid session cookie...

CVE-2025-65590

MEDIUM CVSS 5.4 Dec 16, 2025

nopCommerce 4.90.0 contains a stored cross-site scripting vulnerability in the blog posts functionality of its content management system. Attackers can inject malicious scripts that execute when admin...

CVE-2025-65591

MEDIUM CVSS 5.4 Dec 16, 2025

nopCommerce 4.90.0 contains a cross-site scripting vulnerability in its Currencies functionality that allows attackers to inject malicious scripts into web pages. This affects administrators and users...

CVE-2025-65592

MEDIUM CVSS 6.1 Dec 16, 2025

nopCommerce 4.90.0 has a stored cross-site scripting (XSS) vulnerability in product management functionality. Attackers can inject malicious scripts into product name and short description fields, whi...

CVE-2025-65589

MEDIUM CVSS 6.1 Dec 16, 2025

nopCommerce 4.90.0 contains a cross-site scripting vulnerability in the Attributes functionality that allows attackers to inject malicious scripts into web pages. This affects all users of nopCommerce...

CVE-2024-38963

MEDIUM CVSS 6.1 Jul 9, 2024

This vulnerability allows attackers to inject malicious scripts into product review fields in nopCommerce 4.70.1. When users view these reviews, the scripts execute in their browsers, potentially stea...