github.com
https://github.com/frappe/lms/commit/b8283860a7f029ea2fa0245131c398c079088921 CVE-2026-34606
MEDIUM
Stored XSS in Frappe LMS
Record summary
CVE-2026-34606 has a selected CVSS score of 6.9 (medium).
Description
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, Frappe LMS was vulnerable to stored XSS. This issue has been patched in version 2.48.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 3, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | >= 2.27.0, < 2.48.0 | affected |
References
4github.com
https://github.com/frappe/lms/pull/2185 github.com
https://github.com/frappe/lms/releases/tag/v2.48.0 github.comConfirmation
https://github.com/frappe/lms/security/advisories/GHSA-qf5w-r34q-c7j2