github.comConfirmation
https://github.com/frappe/frappe/security/advisories/GHSA-2wx6-8gmq-x4fw CVE-2026-44205
MEDIUM
Frappe: Stored Cross-Site Scripting (XSS) in User Profile through Image Upload
Record summary
CVE-2026-44205 has a selected CVSS score of 6.9 (medium).
Description
Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user profile image section allows an attacker to execute malicious scripts in the browsers of other users. This issue has been patched in version 15.106.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 12, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
frappeBrowse frappe / frappe | CVE List | < 15.106.0 | affected |