Showing 1 vulnerability on this page for crm

Signals CISA KEV Ransomware Nuclei
frappe vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Frappe CRM vulnerable to authenticated XSS via website field

Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could set crafted URLs in a website field, which were not sanitized, causing cross-site scripting. Version 1.56.2 fixes the issue. No known workarounds are available.

CWE-79Dec 29, 2025
CVSS5.4v3.1EPSS0.176%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX