CVE-2026-28436
Received
Received - Intake
Stored XSS in Frappe Avatar Image URL Allows Remote Exploitation
Publication date: 2026-03-05
Last updated on: 2026-04-29
Assigner: GitHub, Inc.
Description
Description
Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted image URL that results in XSS when the avatar is displayed, and it can be triggered for other users via website page comments. This issue has been patched in versions 16.11.0 and 15.102.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| frappe | frappe | to 15.102.0 (exc) |
| frappe | frappe | From 16.0.0 (inc) to 16.11.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |