Vulnerabilities (CVE)

Filtered by vendor Nopcommerce Subscribe
Filtered by product Nopcommerce
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-28451 1 Nopcommerce 1 Nopcommerce 2022-05-10 5.0 MEDIUM 7.5 HIGH
nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.
CVE-2019-19685 1 Nopcommerce 1 Nopcommerce 2019-12-17 6.8 MEDIUM 8.8 HIGH
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.
CVE-2019-19684 1 Nopcommerce 1 Nopcommerce 2019-12-11 6.5 MEDIUM 8.8 HIGH
nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure because it is possible to upload a crafted Facebook Auth plugin.