CVE-2026-31879
Frappe <14.100.2/15.101.0/16.10.0 - XSS
Title source: llmDescription
Frappe is a full-stack web application framework. Prior to 14.100.2, 15.101.0, and 16.10.0, due to a lack of validation and improper permission checks, users could modify other user's private workspaces. Specially crafted requests could lead to stored XSS here. This vulnerability is fixed in 14.100.2, 15.101.0, and 16.10.0.
Scores
Classification
CWE
CWE-79
Status
draft
Timeline
Published
Mar 11, 2026
Tracked Since
Mar 12, 2026