PatchSiren cyber security CVE debrief
CVE-2026-46546 Frappe CVE debrief
CVE-2026-46546 is a vulnerability in Frappe Learning Management System (LMS) prior to version 2.53.0. An authenticated user could supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigate to an attacker-chosen URL. This issue has been patched in version 2.53.0. The CVSS score for this vulnerability is 2.1, indicating a low severity.
- Vendor
- Frappe
- Product
- Learning Management System (LMS)
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-10
- Original CVE updated
- 2026-07-09
- Advisory published
- 2026-06-10
- Advisory updated
- 2026-07-09
Who should care
Users of Frappe Learning Management System (LMS) prior to version 2.53.0 should be aware of this vulnerability and take steps to patch their systems.
Technical summary
CVE-2026-46546 is a vulnerability in Frappe Learning Management System (LMS) prior to version 2.53.0 that allows an authenticated user to supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigate to an attacker-chosen URL.
Defensive priority
Low
Recommended defensive actions
- Update Frappe Learning Management System (LMS) to version 2.53.0 or later.
Evidence notes
CVE-2026-46546 has been patched in version 2.53.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46546 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46546
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46546 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46546
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/frappe/lms/security/advisories/GHSA-2x47-gr9q-w6fv
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.