PatchSiren cyber security CVE debrief
CVE-2026-47739 frappe CVE debrief
CVE-2026-47739 is a MEDIUM severity vulnerability in Frappe, a full-stack web application framework. The vulnerability is due to lack of sanitization in Note, which allows for stored XSS. This issue has been patched in versions 15.106.0 and 16.16.0.
- Vendor
- frappe
- Product
- Unknown
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-12
- Original CVE updated
- 2026-06-12
- Advisory published
- 2026-06-12
- Advisory updated
- 2026-06-12
Who should care
Users of Frappe framework, especially those who use Note feature, should upgrade to versions 15.106.0 or 16.16.0 to prevent potential XSS attacks.
Technical summary
The vulnerability has a CVSS score of 6.9 and is classified as CWE-79. The CVSS vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.
Defensive priority
MEDIUM
Recommended defensive actions
- Upgrade to Frappe versions 15.106.0 or 16.16.0 or later.
Evidence notes
The vulnerability was published on 2026-06-12T15:16:29.553Z and modified on 2026-06-12T15:56:54.563Z.
Official resources
-
CVE-2026-47739 CVE record
CVE.org
-
CVE-2026-47739 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
CVE-2026-47739 was published on 2026-06-12T15:16:29.553Z.