nopCommerce 4.90.0: When Your Products Get a Little Too Interactive!
Attention e-commerce adventurers! NopCommerce 4.90.0 has a bug in the product management section where malicious scripts can hitch a ride, thanks to cross-site scripting (XSS). Your “Product Name” and “Short Description” fields are the new danger zones. So, watch out before your site becomes a JavaScript jamboree!

Hot Take:
Looks like nopCommerce 4.90.0 just got a new feature: unintentional JavaScript party crashers in your product names and descriptions! Who knew e-commerce could be so exciting… or should I say, alarming? Someone get the IT department on the line stat—before your next product upload turns into a cyber circus!
Key Points:
- Vulnerability: Stored Cross-Site Scripting (XSS) detected in nopCommerce 4.90.0.
- Affected Areas: Product Name and Short Description fields in product management functionality.
- Impact: Malicious scripts stored in the backend execute when viewed by users.
- CVE Code: CVE-2025-65592 has been assigned to this vulnerability.
- Discovered by: Security firm AlterSec, operating under PenTest.NZ.
Already a member? Log in here
