Vulnerabilities
Vulnerable Software
nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid session cookie access to privileged endpoints (such as /admin) even after the legitimate user has logged out, enabling session hijacking. Any version above 4.70 that is not 4.80.3 fixes the vulnerability.
CVSS Score
7.1
EPSS Score
0.0
Published
2025-12-01
nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.
CVSS Score
3.5
EPSS Score
0.0
Published
2025-04-16
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-10-19


Contact Us

Shodan ® - All rights reserved