CVE-2019-11519: Nopcommerce
Medium severity, CVSS 4.9. EPSS: 1.2% chance of exploitation in the next 30 days.
Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen.
Affected products
- Nopcommerce Nopcommerce: up to and including 4.10
Published 2019-04-25. Last modified 2026-06-17.