Vulnerabilities > Nopcommerce > High

DATE CVE VULNERABILITY TITLE RISK
2022-10-19 CVE-2022-33077 Authorization Bypass Through User-Controlled Key vulnerability in Nopcommerce
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.
network
low complexity
nopcommerce CWE-639
7.5
2022-05-02 CVE-2022-28451 Path Traversal vulnerability in Nopcommerce 4.50.1
nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.
network
low complexity
nopcommerce CWE-22
7.5
2019-12-09 CVE-2019-19685 Cross-Site Request Forgery (CSRF) vulnerability in Nopcommerce 4.20
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.
network
low complexity
nopcommerce CWE-352
8.8
2019-12-09 CVE-2019-19684 Unrestricted Upload of File with Dangerous Type vulnerability in Nopcommerce 4.20
nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure because it is possible to upload a crafted Facebook Auth plugin.
network
low complexity
nopcommerce CWE-434
8.8