CVE-2025-65592 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and…
Medium CVSS: 6.1

CVE-2025-65592

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields are stored in the backend database and executed automatically whenever a user views the affected pages.
Vendor
Nopcommerce
Product
Nopcommerce
CWE
CWE-79
Yayın Tarihi
2025-12-16 19:15:58
Güncelleme
2025-12-19 16:40:13
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar