nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Oct 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Fri, 03 Oct 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-03T19:02:31.330Z
Reserved: 2021-10-11T00:00:00.000Z
Link: CVE-2021-42193

Updated: 2025-10-03T19:02:24.722Z

Status : Received
Published: 2025-10-03T17:15:45.883
Modified: 2025-10-03T19:15:40.657
Link: CVE-2021-42193

No data.

No data.