Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2025-65593 nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality. Nopcommerce Mitigation only Fix from $1,9502025-12-16 MEDIUM 6.1 CVE-2025-65592 nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product… Nopcommerce Mitigation only Fix from $1,6002025-12-16 MEDIUM 5.4 CVE-2025-65590 nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Management area. Nopcommerce Mitigation only Fix from $1,6002025-12-16 MEDIUM 5.4 CVE-2025-65591 nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality. Nopcommerce Mitigation only Fix from $1,6002025-12-16 MEDIUM 6.1 CVE-2025-65589 nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality. Nopcommerce No fix yet Fix from $1,6002025-12-16 MEDIUM 6.1 CVE-2021-42193 nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payl… Nopcommerce No fix yet Fix from $1,6002025-10-03 MEDIUM 6.1 CVE-2024-38963 Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProductReview.ReviewText" parameter(… Nopcommerce No fix yet Fix from $1,6002024-07-09 MEDIUM 6.1 CVE-2022-28449 nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the … Nopcommerce No fix yet Fix from $1,6002022-04-26 MEDIUM 5.4 CVE-2022-28450 nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote atta… Nopcommerce No fix yet Fix from $1,6002022-04-26 MEDIUM 5.4 CVE-2022-28448 nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at … Nopcommerce No fix yet Fix from $1,6002022-04-26 MEDIUM 6.1 CVE-2021-26916 In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through th… Nopcommerce No fix yet Fix from $1,6002021-02-08 CRITICAL 9.1 CVE-2019-19683 RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/ProcessRequest because of Librar… Nopcommerce No fix yet Fix from $2,3002019-12-09 HIGH 8.8 CVE-2019-19684 nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/Facebook… Nopcommerce No fix yet Fix from $1,9502019-12-09 HIGH 8.8 CVE-2019-19685 RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions. Nopcommerce No fix yet Fix from $1,9502019-12-09