Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2022-26954

Disclosure Date: October 20, 2022 (last updated February 24, 2025)
Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePassword function, (2) SignInCustomerAsync function, (3) SuccessfulAuthentication method, or (4) NopRedirectResultExecutor class.
Attacker Value
Unknown

CVE-2022-33077

Disclosure Date: October 19, 2022 (last updated February 24, 2025)
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.
Attacker Value
Unknown

CVE-2022-27461

Disclosure Date: May 04, 2022 (last updated February 23, 2025)
In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.
Attacker Value
Unknown

CVE-2022-28451

Disclosure Date: May 02, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.
Attacker Value
Unknown

CVE-2022-28450

Disclosure Date: April 26, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.
Attacker Value
Unknown

CVE-2022-28449

Disclosure Date: April 26, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system.
Attacker Value
Unknown

CVE-2022-28448

Disclosure Date: April 26, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.
Attacker Value
Unknown

CVE-2021-26916

Disclosure Date: February 08, 2021 (last updated February 22, 2025)
In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discountcode parameter.
Attacker Value
Unknown

CVE-2020-29475

Disclosure Date: December 29, 2020 (last updated February 22, 2025)
nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability can allow an attacker to inject the XSS payload in Schedule tasks and each time any user will go to that page of the website, the XSS triggers and attacker can able to steal the cookie according to the crafted payload.
Attacker Value
Unknown

CVE-2019-19685

Disclosure Date: December 09, 2019 (last updated November 27, 2024)
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.