Frappe Framework
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Frappe Framework.
By the Year
In 2026 there have been 12 vulnerabilities in Frappe Framework.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 12 | 0.00 |
It may take a day or so for new Frappe Framework vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Frappe Framework Security Vulnerabilities
Frappe Framework 17.0.0-dev: XSS in frappe.ui.Tree Component
CVE-2026-50712
- June 24, 2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component
XSS
Stored XSS in Frappe Framework 17.0.0-dev Number Card
CVE-2026-50711
- June 24, 2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component.
XSS
Stored XSS in Frappe Framework 17.0.0-dev Number Card eval
CVE-2026-50710
- June 24, 2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.
XSS
Stored XSS in Frappe Framework 17.0.0-dev Notifications Events Panel
CVE-2026-50709
- June 24, 2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.
XSS
Stored XSS in MultiSelectDialog of Frappe Framework 17.0.0-dev
CVE-2026-50708
- June 24, 2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component.
XSS
Frappe Framework 17.0.0-dev XSS via Form Dashboard headline renderer
CVE-2026-50705
- June 24, 2026
A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer.
XSS
Stored XSS in Frappe 17.0-dev Breadcrumb Renderer
CVE-2026-50704
- June 24, 2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer.
XSS
Stored XSS in Frappe Framework 17.0.0-dev Desk Icon Renderer
CVE-2026-50703
- June 24, 2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer.
XSS
R-XSS in Frappe Framework 17.0.0-dev via dashboard-view
CVE-2026-50701
- June 24, 2026
A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component.
XSS
Stored XSS in frappe.get_avatar (Frappe Framework 17.0.0-dev)
CVE-2026-50700
- June 24, 2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function.
XSS
Frappe Framework 17.0.0-dev: Stored XSS via Auto Repeat reference_document
CVE-2026-50699
- June 24, 2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto Repeat form.
XSS
Frappe Fwk 17.0.0-dev Stored XSS in Audit Trail
CVE-2026-50698
- June 24, 2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HTML output in the Audit Trail component.
XSS
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Frappe Framework or by Frappe? Click the Watch button to subscribe.