CVE-2025-65592

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields are stored in the backend database and executed automatically whenever a user views the affected pages.
References
Link Resource
https://seclists.org/fulldisclosure/2025/Dec/19 Mailing List Third Party Advisory
https://www.nopcommerce.com/ Product
http://seclists.org/fulldisclosure/2025/Dec/19 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:nopcommerce:nopcommerce:4.90.0:*:*:*:*:*:*:*

History

19 Dec 2025, 16:40

Type Values Removed Values Added
First Time Nopcommerce
Nopcommerce nopcommerce
CPE cpe:2.3:a:nopcommerce:nopcommerce:4.90.0:*:*:*:*:*:*:*
References () https://seclists.org/fulldisclosure/2025/Dec/19 - () https://seclists.org/fulldisclosure/2025/Dec/19 - Mailing List, Third Party Advisory
References () https://www.nopcommerce.com/ - () https://www.nopcommerce.com/ - Product
References () http://seclists.org/fulldisclosure/2025/Dec/19 - () http://seclists.org/fulldisclosure/2025/Dec/19 - Mailing List, Third Party Advisory

17 Dec 2025, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79

16 Dec 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-16 19:15

Updated : 2025-12-19 16:40


NVD link : CVE-2025-65592

Mitre link : CVE-2025-65592

CVE.ORG link : CVE-2025-65592


JSON object : View

Products Affected

nopcommerce

  • nopcommerce
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')