nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields are stored in the backend database and executed automatically whenever a user views the affected pages.
References
| Link | Resource |
|---|---|
| https://seclists.org/fulldisclosure/2025/Dec/19 | Mailing List Third Party Advisory |
| https://www.nopcommerce.com/ | Product |
| http://seclists.org/fulldisclosure/2025/Dec/19 | Mailing List Third Party Advisory |
Configurations
History
19 Dec 2025, 16:40
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Nopcommerce
Nopcommerce nopcommerce |
|
| CPE | cpe:2.3:a:nopcommerce:nopcommerce:4.90.0:*:*:*:*:*:*:* | |
| References | () https://seclists.org/fulldisclosure/2025/Dec/19 - Mailing List, Third Party Advisory | |
| References | () https://www.nopcommerce.com/ - Product | |
| References | () http://seclists.org/fulldisclosure/2025/Dec/19 - Mailing List, Third Party Advisory |
17 Dec 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| CWE | CWE-79 |
16 Dec 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-16 19:15
Updated : 2025-12-19 16:40
NVD link : CVE-2025-65592
Mitre link : CVE-2025-65592
CVE.ORG link : CVE-2025-65592
JSON object : View
Products Affected
nopcommerce
- nopcommerce
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
