CVE-2025-65593: Nopcommerce

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.

Affected products

Published 2025-12-16. Last modified 2026-10-05.