๐Ÿ” CVE Alert

CVE-2026-3673

UNKNOWN 0.0

Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where tags are rendered. The vulnerable renderer interpolates tag content into HTML attributes and element content without escaping. This issue affects Frappe: 16.10.10.

CWE CWE-79
Vendor frappe
Product frappe
Published Apr 22, 2026
Last Updated Apr 22, 2026
Stay Ahead of the Next One

Get instant alerts for frappe frappe

Be the first to know when new unknown vulnerabilities affecting frappe frappe are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Frappe / Frappe
16.10.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
fluidattacks.com: https://fluidattacks.com/es/advisories/silvio github.com: https://github.com/frappe/frappe

Credits

Fluid Attacks' AI SAST Scanner Oscar Uribe