Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted image URL that results in XSS when the avatar is displayed, and it can be triggered for other users via website page comments. This issue has been patched in versions 16.11.0 and 15.102.0.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted image URL that results in XSS when the avatar is displayed, and it can be triggered for other users via website page comments. This issue has been patched in versions 16.11.0 and 15.102.0. | |
| Title | Frappe: Stored XSS in avatar_macro.html | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-05T20:21:35.392Z
Reserved: 2026-02-27T15:54:05.139Z
Link: CVE-2026-28436
No data.
Status : Received
Published: 2026-03-05T21:16:22.180
Modified: 2026-03-05T21:16:22.180
Link: CVE-2026-28436
No data.
OpenCVE Enrichment
No data.