ZeroHour

CVE-2026-38432

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p7
Published
()
Modified
Description

ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when the template is applied.

Vendors
frappe
Products
erpnext
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.