CVE-2025-65592

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields are stored in the backend database and executed automatically whenever a user views the affected pages.
References
Link Resource
https://seclists.org/fulldisclosure/2025/Dec/19 Mailing List Third Party Advisory
https://www.nopcommerce.com/ Product
http://seclists.org/fulldisclosure/2025/Dec/19 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:nopcommerce:nopcommerce:4.90.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-16 19:15

Updated : 2025-12-19 16:40


NVD link : CVE-2025-65592

Mitre link : CVE-2025-65592

CVE.ORG link : CVE-2025-65592


JSON object : View

Products Affected

nopcommerce

  • nopcommerce
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')