Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Nopcommerce HIGH 8.8
CVE-2025-65593

nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.

Mitigation only
Fix from $1,950 2025-12-16
Nopcommerce MEDIUM 6.1
CVE-2025-65592

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product…

Mitigation only
Fix from $1,600 2025-12-16
Nopcommerce MEDIUM 5.4
CVE-2025-65590

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Management area.

Mitigation only
Fix from $1,600 2025-12-16
Nopcommerce MEDIUM 5.4
CVE-2025-65591

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality.

Mitigation only
Fix from $1,600 2025-12-16
Nopcommerce MEDIUM 6.1
CVE-2025-65589

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality.

No fix yet
Fix from $1,600 2025-12-16
Nopcommerce MEDIUM 6.1
CVE-2021-42193

nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payl…

No fix yet
Fix from $1,600 2025-10-03
Nopcommerce MEDIUM 6.1
CVE-2024-38963

Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProductReview.ReviewText" parameter(…

No fix yet
Fix from $1,600 2024-07-09
Nopcommerce MEDIUM 6.1
CVE-2022-28449

nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the …

No fix yet
Fix from $1,600 2022-04-26
Nopcommerce MEDIUM 5.4
CVE-2022-28450

nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote atta…

No fix yet
Fix from $1,600 2022-04-26
Nopcommerce MEDIUM 5.4
CVE-2022-28448

nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at …

No fix yet
Fix from $1,600 2022-04-26
Nopcommerce MEDIUM 6.1
CVE-2021-26916

In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through th…

No fix yet
Fix from $1,600 2021-02-08
Nopcommerce CRITICAL 9.1
CVE-2019-19683

RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/ProcessRequest because of Librar…

No fix yet
Fix from $2,300 2019-12-09
Nopcommerce HIGH 8.8
CVE-2019-19684

nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/Facebook…

No fix yet
Fix from $1,950 2019-12-09
Nopcommerce HIGH 8.8
CVE-2019-19685

RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.

No fix yet
Fix from $1,950 2019-12-09