github.com
https://github.com/frappe/crm/commit/c5766d9989131d17d954e866bfc4b8d3b23e4f10 CVE-2025-68928
MEDIUM
Frappe CRM vulnerable to authenticated XSS via website field
Record summary
CVE-2025-68928 has a selected CVSS score of 5.4 (medium).
Description
Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could set crafted URLs in a website field, which were not sanitized, causing cross-site scripting. Version 1.56.2 fixes the issue. No known workarounds are available.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 29, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 1.56.2 | affected |
References
3github.com
https://github.com/frappe/crm/releases/tag/v1.56.2 github.comConfirmation
https://github.com/frappe/crm/security/advisories/GHSA-fm34-v6j7-chwc