CVE 5.1 MEDIUM

ERPNext 16.16.0 – Stored XSS in POS customer section via unescaped template literals_CVE-2026-42840

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Description

An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of Sale (POS) interface for every operator who selects that customer.
This issue affects ERPNext: 16.16.0.

Basic Information

ID CVE-2026-42840
Source Fluid Attacks
Published Jun 3, 2026 at 17:35

Affected Product

Vendor Frappe
Product ERPNext
Version 16.16.0
Affected Versions Frappe ERPNext 16.16.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.