CVE-2026-47739: medium-severity vulnerability in frappe
Frappe: Stored XSS in Note
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.9epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possible due to lack of sanitization. This issue has been patched in versions 15.106.0 and 16.16.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
frappe · frappeRelated CVEs — frappe
In the same product, most dangerous first.
CVE-2023-46127MEDIUMFrappe vulnerable to HTML injection by any Desk userEPSS 37.0%CVE-2026-39352HIGHFrappe has an Arbitrary File Read via Path Traversal in render_includeEPSS 1.3%CVE-2022-23055—ERPNext - Improper user access conrolEPSS 1.2%CVE-2022-23058—ERPNext - Stored XSS in My SettingsEPSS 0.9%CVE-2026-66002MEDIUMFrappe: User Enumeration via PDDREPSS 0.8%CVE-2025-30213MEDIUMFrappe has Possibility of Remote Code Execution due to improper validationEPSS 0.7%