CVE-2019-19685: Nopcommerce

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.

Affected products

Published 2019-12-09. Last modified 2026-06-17.