๐Ÿ” CVE Alert

CVE-2026-3837

UNKNOWN 0.0

Frappe Framework 16.10.0 - Stored DOM XSS in Multiple Field Formatters

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the affected document in Desk. The vulnerable formatter implementations interpolate stored values into raw HTML attributes and element content without escaping This issue affects Frappe: 16.10.0.

CWE CWE-79
Vendor frappe
Product frappe
Published Apr 22, 2026
Stay Ahead of the Next One

Get instant alerts for frappe frappe

Be the first to know when new unknown vulnerabilities affecting frappe frappe are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Frappe / Frappe
16.10.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
fluidattacks.com: https://fluidattacks.com/es/advisories/sabina github.com: https://github.com/frappe/frappe

Credits

Fluid Attacks' AI SAST Scanner Oscar Uribe