๐Ÿ” CVE Alert

CVE-2026-49391

UNKNOWN 0.0

Frappe: Stored XSS in Column Headers via Data Import

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering previews and results, allowing an authenticated importer to persist script content that executes when another user views the import interface. This issue is fixed in versions 16.19.0 and 15.109.0.

CWE CWE-79
Vendor frappe
Product frappe
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for frappe frappe

Be the first to know when new unknown vulnerabilities affecting frappe frappe are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

frappe / frappe
>= 16.0.0-beta.1, < 16.19.0 < 15.109.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frappe/frappe/security/advisories/GHSA-7f28-gm9h-q6rg github.com: https://github.com/frappe/frappe/commit/002a36a2668781366e4bf1ff144da5e53446f540 github.com: https://github.com/frappe/frappe/commit/2bf7b9d0b4c7f815de1c85695e9a027ecce8bed9