nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields are stored in the backend database and executed automatically whenever a user views the affected pages.
References
| Link | Resource |
|---|---|
| https://seclists.org/fulldisclosure/2025/Dec/19 | Mailing List Third Party Advisory |
| https://www.nopcommerce.com/ | Product |
| http://seclists.org/fulldisclosure/2025/Dec/19 | Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-12-16 19:15
Updated : 2025-12-19 16:40
NVD link : CVE-2025-65592
Mitre link : CVE-2025-65592
CVE.ORG link : CVE-2025-65592
JSON object : View
Products Affected
nopcommerce
- nopcommerce
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
