PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46546 Frappe CVE debrief

CVE-2026-46546 is a vulnerability in Frappe Learning Management System (LMS) prior to version 2.53.0. An authenticated user could supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigate to an attacker-chosen URL. This issue has been patched in version 2.53.0. The CVSS score for this vulnerability is 2.1, indicating a low severity.

Vendor
Frappe
Product
Learning Management System (LMS)
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-10
Original CVE updated
2026-07-09
Advisory published
2026-06-10
Advisory updated
2026-07-09

Who should care

Users of Frappe Learning Management System (LMS) prior to version 2.53.0 should be aware of this vulnerability and take steps to patch their systems.

Technical summary

CVE-2026-46546 is a vulnerability in Frappe Learning Management System (LMS) prior to version 2.53.0 that allows an authenticated user to supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigate to an attacker-chosen URL.

Defensive priority

Low

Recommended defensive actions

  • Update Frappe Learning Management System (LMS) to version 2.53.0 or later.

Evidence notes

CVE-2026-46546 has been patched in version 2.53.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46546 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46546

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46546 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46546

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.