Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nopcommerce

First CVE: Apr 25, 2019Active for: 7 yearsTotal CVEs: 23
32.1
VTI Score
Medium

nopCommerce is a modestly represented e-commerce platform that, despite a narrow product footprint, ranks among the more prominent vendors in the vulnerability landscape due to widespread deployment in online retail and small-business storefronts. The vendor's exposure centers on web-application input-handling and session-management weaknesses, with recurring patterns of cross-site scripting, cross-site request forgery, path traversal, open redirect, and authorization-bypass flaws that are typical of server-side commerce platforms managing user input and access control. These weakness classes reflect the inherent complexity of building authentication, file-access, and navigation logic into a multi-tenant storefront system where user trust boundaries are critical. Defenders should treat nopCommerce instances as components requiring careful input validation and access-control review; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nopcommerce over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 25, 2019
7 years ago
Most Recent CVE
Dec 16, 2025
220 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-65593HIGH
nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.
Dec 16, 20258.827NONO
CVE-2022-33077HIGH
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.
Oct 19, 20227.527NONO
CVE-2025-11699HIGH
nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid session cookie ac
Dec 1, 20257.126NONO
CVE-2020-29475MEDIUM
nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability can allow an attacker to inject the XSS payload in Schedule ta
Dec 29, 20204.826NOYES
CVE-2019-19684HIGH
nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure becaus
Dec 9, 20198.826NONO
CVE-2019-19683CRITICAL
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/ProcessRequest because of Libraries/Nop.Services/Media/RoxyFile
Dec 9, 20199.126NONO
CVE-2022-28451HIGH
nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.
May 2, 20227.525NONO
CVE-2019-19685HIGH
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.
Dec 9, 20198.825NONO
CVE-2021-42193MEDIUM
nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires.
Oct 3, 20256.123NONO
CVE-2022-27461MEDIUM
In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.
May 4, 20226.122NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
65%
26%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (95.7%)
High1 (4.3%)
Unknown0 (0.0%)
User Interaction
None6 (26.1%)
Unknown0 (0.0%)
Required17 (73.9%)
Privileges Required
Low6 (26.1%)
High4 (17.4%)
None13 (56.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nopcommerce.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nopcommerce — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nopcommerce's Products

View all 2 CNAs →

Top CWEs