CVE-2025-65592

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
16/12/2025
Last modified:
19/12/2025

Description

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields are stored in the backend database and executed automatically whenever a user views the affected pages.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nopcommerce:nopcommerce:4.90.0:*:*:*:*:*:*:*