Watch Your Wallet: nopCommerce 4.90.0’s Currency XSS Slip-up!
Attention shoppers: nopCommerce 4.90.0 is offering a new deal—Cross Site Scripting vulnerability via the Currencies feature! Forget coupons; just tweak the “Custom formatting” field and watch the chaos unfold in Bestsellers, Orders, and product views. Secure shopping? Not today!

Hot Take:
Well, well, well, if it isn’t another XSS vulnerability sneaking into our online shopping carts. It seems like nopCommerce 4.90.0 is offering a little more than just currencies — surprise, it’s a vulnerability buffet! Remember folks, not all that glitters is gold, especially when it’s a shiny new piece of malicious script. Time to patch up before your online store turns into a hacker’s dream playground!
Key Points:
- nopCommerce 4.90.0 has a Stored XSS vulnerability.
- The vulnerability resides in the “Currencies” functionality.
- XSS can be triggered when accessing Bestsellers, Sales Orders, or viewing products.
- Vulnerability discovered by AlterSec, using PenTest.NZ.
- CVE-2025-65591 has been assigned to this vulnerability.
Already a member? Log in here
