CVE-2019-11519: Nopcommerce

Medium severity, CVSS 4.9. EPSS: 1.2% chance of exploitation in the next 30 days.

Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen.

Affected products

Published 2019-04-25. Last modified 2026-06-17.