CVE-2026-50712
Received
Received - Intake
Stored XSS in Frappe Framework
Publication date: 2026-06-24
Last updated on: 2026-06-24
Assigner: Fluid Attacks
Description
Description
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| frappe | framework | to 17.0.0-dev (exc) |
| frappe | framework | 17.0.0-dev |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |