Frappe Framework Frappe Framework

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Frappe Framework.

By the Year

In 2026 there have been 12 vulnerabilities in Frappe Framework.

Year Vulnerabilities Average Score
2026 12 0.00

It may take a day or so for new Frappe Framework vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Frappe Framework Security Vulnerabilities

Frappe Framework 17.0.0-dev: XSS in frappe.ui.Tree Component
CVE-2026-50712 - June 24, 2026

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component

XSS

Stored XSS in Frappe Framework 17.0.0-dev Number Card
CVE-2026-50711 - June 24, 2026

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component.

XSS

Stored XSS in Frappe Framework 17.0.0-dev Number Card eval
CVE-2026-50710 - June 24, 2026

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.

XSS

Stored XSS in Frappe Framework 17.0.0-dev Notifications Events Panel
CVE-2026-50709 - June 24, 2026

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.

XSS

Stored XSS in MultiSelectDialog of Frappe Framework 17.0.0-dev
CVE-2026-50708 - June 24, 2026

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component.

XSS

Frappe Framework 17.0.0-dev XSS via Form Dashboard headline renderer
CVE-2026-50705 - June 24, 2026

A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer.

XSS

Stored XSS in Frappe 17.0-dev Breadcrumb Renderer
CVE-2026-50704 - June 24, 2026

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer.

XSS

Stored XSS in Frappe Framework 17.0.0-dev Desk Icon Renderer
CVE-2026-50703 - June 24, 2026

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer.

XSS

R-XSS in Frappe Framework 17.0.0-dev via dashboard-view
CVE-2026-50701 - June 24, 2026

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component.

XSS

Stored XSS in frappe.get_avatar (Frappe Framework 17.0.0-dev)
CVE-2026-50700 - June 24, 2026

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function.

XSS

Frappe Framework 17.0.0-dev: Stored XSS via Auto Repeat reference_document
CVE-2026-50699 - June 24, 2026

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto Repeat form.

XSS

Frappe Fwk 17.0.0-dev Stored XSS in Audit Trail
CVE-2026-50698 - June 24, 2026

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HTML output in the Audit Trail component.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Frappe Framework or by Frappe? Click the Watch button to subscribe.

Frappe
Vendor

subscribe