Vulnerabilities > Nopcommerce > Nopcommerce > 3.80
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-10-19 | CVE-2022-33077 | Authorization Bypass Through User-Controlled Key vulnerability in Nopcommerce An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint. | 7.5 |
2022-05-04 | CVE-2022-27461 | Open Redirect vulnerability in Nopcommerce In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link. | 6.1 |
2019-04-25 | CVE-2019-11519 | XXE vulnerability in Nopcommerce Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen. | 4.9 |