CVE-2026-3837
Frappe Framework 16.10.0 - Stored DOM XSS in Multiple Field Formatters
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the affected document in Desk. The vulnerable formatter implementations interpolate stored values into raw HTML attributes and element content without escaping This issue affects Frappe: 16.10.0.
| CWE | CWE-79 |
| Vendor | frappe |
| Product | frappe |
| Published | Apr 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for frappe frappe
Be the first to know when new unknown vulnerabilities affecting frappe frappe are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Frappe / Frappe
16.10.0
References
Credits
Fluid Attacks' AI SAST Scanner Oscar Uribe