CVE-2024-58248: Nopcommerce
Low severity, CVSS 3.5. EPSS: 0.4% chance of exploitation in the next 30 days.
nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.
Affected products
- Nopcommerce Nopcommerce: before 4.80.0 (fixed in 4.80.0)
Published 2025-04-16. Last modified 2026-06-17.