---
id: CVE-2025-65592
title: >-
  nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product
  management functionality
summary: >-
  nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product
  management functionality. Malicious payloads inserted into the "Product Name"
  and "Short Description" fields are stored in the backend database and executed
  au…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: nopcommerce
product: nopcommerce
affected:
  - nopcommerce = 4.90.0
published: '2025-12-16'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T18:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-65592'
references:
  - url: 'https://seclists.org/fulldisclosure/2025/Dec/19'
    label: cve@mitre.org
  - url: 'https://www.nopcommerce.com/'
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2025/Dec/19'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.0026
epssPercentile: 0.1616
ingestedAt: '2026-10-05T18:29:11.151Z'
---

## Overview

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields are stored in the backend database and executed automatically whenever a user views the affected pages.

## Affected

- `nopcommerce = 4.90.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
