Nopcommerce
Nopcommerce: vulnerabilidades y CVE
Nopcommerce tiene 22 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-65593 | Alta (8.8) | 0.29% | — | 16 dic 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality. |
| CVE-2025-65592 | Media (6.1) | 0.26% | — | 16 dic 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields are stored in the backend… |
| CVE-2025-65591 | Media (5.4) | 0.24% | — | 16 dic 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality. |
| CVE-2025-65590 | Media (5.4) | 0.23% | — | 16 dic 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Management area. |
| CVE-2025-65589 | Media (6.1) | 0.36% | — | 16 dic 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality. |
| CVE-2025-11699 | Alta (7.1) | 0.43% | — | 1 dic 2025 | nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid session cookie access to privileged endpoints (such as… |
| CVE-2021-42193 | Media (6.1) | 0.23% | — | 3 oct 2025 | nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires. |
| CVE-2024-58248 | Baja (3.5) | 0.35% | — | 16 abr 2025 | nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards. |
| CVE-2024-38963 | Media (6.1) | 0.27% | — | 9 jul 2024 | Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProductReview.ReviewText" parameter(s) (Reviews) when creating a new review. |
| CVE-2022-26954 | Media (6.1) | 0.72% | — | 20 oct 2022 | Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed… |
| CVE-2022-33077 | Alta (7.5) | 0.71% | — | 19 oct 2022 | An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint. |
| CVE-2022-27461 | Media (6.1) | 0.71% | — | 4 may 2022 | In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link. |
| CVE-2022-28451 | Alta (7.5) | 1.6% | — | 2 may 2022 | nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature. |
| CVE-2022-28450 | Media (5.4) | 0.71% | — | 26 abr 2022 | nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser. |
| CVE-2022-28449 | Media (6.1) | 0.72% | — | 26 abr 2022 | nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system. |
| CVE-2022-28448 | Media (5.4) | 0.49% | — | 26 abr 2022 | nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info. |
| CVE-2021-26916 | Media (6.1) | 1.1% | — | 8 feb 2021 | In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discountcode parameter. |
| CVE-2019-19685 | Alta (8.8) | 0.51% | — | 9 dic 2019 | RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions. |
| CVE-2019-19684 | Alta (8.8) | 1.6% | — | 9 dic 2019 | nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure because it is possible to upload a crafted… |
| CVE-2019-19683 | Crítica (9.1) | 1.8% | — | 9 dic 2019 | RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/ProcessRequest because of Libraries/Nop.Services/Media/RoxyFileman/FileRoxyFilemanService.cs. |
| CVE-2019-19682 | Media (4.8) | 0.56% | — | 9 dic 2019 | nopCommerce through 4.20 allows XSS in the SaveStoreMappings of the components \Presentation\Nop.Web\Areas\Admin\Controllers\NewsController.cs and \Presentation\Nop.Web\Areas\Admin\Controllers\BlogController.cs via Body… |
| CVE-2019-11519 | Media (4.9) | 1.2% | — | 25 abr 2019 | Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.