CVE-2026-44205: fallo de gravedad media en frappe
Frappe: Stored Cross-Site Scripting (XSS) in User Profile through Image Upload
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.9epss 0.4%
probabilidad de explotación
0.4%top 64% de las CVE
explotación observada
noninguna fuente lo reporta
Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user profile image section allows an attacker to execute malicious scripts in the browsers of other users. This issue has been patched in version 15.106.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
frappe · frappeCVEs relacionadas — frappe
En el mismo producto, de las más peligrosas a las menos.
CVE-2023-46127MEDIUMFrappe vulnerable to HTML injection by any Desk userEPSS 37.0%CVE-2026-39352HIGHFrappe has an Arbitrary File Read via Path Traversal in render_includeEPSS 1.3%CVE-2022-23055—ERPNext - Improper user access conrolEPSS 1.2%CVE-2022-23058—ERPNext - Stored XSS in My SettingsEPSS 0.9%CVE-2026-66002MEDIUMFrappe: User Enumeration via PDDREPSS 0.8%CVE-2025-30213MEDIUMFrappe has Possibility of Remote Code Execution due to improper validationEPSS 0.7%