CVE Database
/

CVE-2026-3837

Back to search

CVE-2026-3837

Published: Apr 22, 2026

Modified: Apr 27, 2026

PUBLISHED

Description

An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the affected document in Desk. The vulnerable formatter implementations interpolate stored values into raw HTML attributes and element content without escaping This issue affects Frappe: 16.10.0.

VendorProductVersions

Frappe

Frappe

affected
16.10.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now