CVE 4.6 MEDIUM

Frappe Framework 16.10.0 – Stored DOM XSS in Multiple Field Formatters_CVE-2026-3837

4.6 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the affected document in Desk. The vulnerable formatter implementations interpolate stored values into raw HTML attributes and element content without escaping

This issue affects Frappe: 16.10.0.

Basic Information

ID CVE-2026-3837
Source Fluid Attacks
Published Apr 22, 2026 at 19:52

Affected Product

Vendor Frappe
Product Frappe
Version 16.10.0
Affected Versions Frappe Frappe 16.10.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.