nopCommerce is a modestly represented e-commerce platform that, despite a narrow product footprint, ranks among the more prominent vendors in the vulnerability landscape due to widespread deployment in online retail and small-business storefronts. The vendor's exposure centers on web-application input-handling and session-management weaknesses, with recurring patterns of cross-site scripting, cross-site request forgery, path traversal, open redirect, and authorization-bypass flaws that are typical of server-side commerce platforms managing user input and access control. These weakness classes reflect the inherent complexity of building authentication, file-access, and navigation logic into a multi-tenant storefront system where user trust boundaries are critical. Defenders should treat nopCommerce instances as components requiring careful input validation and access-control review; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nopcommerce over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65593HIGH nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality. | Dec 16, 2025 | 8.8 | 27 | NO | NO |
CVE-2022-33077HIGH An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint. | Oct 19, 2022 | 7.5 | 27 | NO | NO |
CVE-2025-11699HIGH nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a
a valid session cookie ac | Dec 1, 2025 | 7.1 | 26 | NO | NO |
CVE-2020-29475MEDIUM nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability can allow an attacker to inject the XSS payload in Schedule ta | Dec 29, 2020 | 4.8 | 26 | NO | YES |
CVE-2019-19684HIGH nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure becaus | Dec 9, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-19683CRITICAL RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/ProcessRequest because of Libraries/Nop.Services/Media/RoxyFile | Dec 9, 2019 | 9.1 | 26 | NO | NO |
CVE-2022-28451HIGH nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature. | May 2, 2022 | 7.5 | 25 | NO | NO |
CVE-2019-19685HIGH RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions. | Dec 9, 2019 | 8.8 | 25 | NO | NO |
CVE-2021-42193MEDIUM nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires. | Oct 3, 2025 | 6.1 | 23 | NO | NO |
CVE-2022-27461MEDIUM In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link. | May 4, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nopcommerce.
Media articles that mention a CVE ID that affects a product developed by Nopcommerce — matched by CVE ID, not by vendor name.