frappe Vulnerabilities and Affected Products
Vulnerabilities associated with Frappe Framework.
Products
Clear product- frappe62 vulnerabilities
- lms23 vulnerabilities
- erpnext21 vulnerabilities
- Frappe Framework12 vulnerabilities
- press6 vulnerabilities
- hrms4 vulnerabilities
- crm1 vulnerability
- Frappe CRM1 vulnerability
- Frappe HelpDesk1 vulnerability
- frappe/lms1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-50712MEDIUM | Frappe Framework 17.0.0-dev - Stored XSS in Tree View node label renderingA Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component CWE-79Jun 24, 2026 | CVSS4.8v4.0 | EPSS0.239% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50711MEDIUM | Frappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields renderingA Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component. CWE-79Jun 24, 2026 | CVSS4.6v4.0 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50710MEDIUM | Frappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_configA Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component. CWE-79Jun 24, 2026 | CVSS4.6v4.0 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50709MEDIUM | Frappe Framework 17.0.0-dev - Stored XSS in Notifications Events color renderingA Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel. CWE-79Jun 24, 2026 | CVSS4.8v4.0 | EPSS0.239% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50708MEDIUM | Frappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result renderingA Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component. CWE-79Jun 24, 2026 | CVSS4.8v4.0 | EPSS0.239% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50705MEDIUM | Frappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline renderingA Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer. CWE-79Jun 24, 2026 | CVSS4.6v4.0 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50704MEDIUM | Frappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs renderingA Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer. CWE-79Jun 24, 2026 | CVSS4.6v4.0 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50703MEDIUM | Frappe Framework 17.0.0-dev - Stored XSS in Desktop Icon label renderingA Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer. CWE-79Jun 24, 2026 | CVSS4.8v4.0 | EPSS0.239% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50701MEDIUM | Frappe Framework 17.0.0-dev - Reflected DOM XSS in dashboard-view breadcrumb renderingA Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component. CWE-79Jun 24, 2026 | CVSS5.1v4.0 | EPSS0.268% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50700MEDIUM | Frappe Framework 17.0.0-dev - Stored XSS in frappe.get_avatar image renderingA Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function. CWE-79Jun 24, 2026 | CVSS4.6v4.0 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50699MEDIUM | Frappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule renderingA Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto Repeat form. CWE-79Jun 24, 2026 | CVSS4.6v4.0 | EPSS0.313% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50698MEDIUM | Frappe Framework 17.0.0-dev - Stored XSS in Audit Trail template renderingA Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HTML output in the Audit Trail component. CWE-79Jun 24, 2026 | CVSS4.6v4.0 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |