PT-2026-37089 · Frappe · Erpnext

C0Wking

·

Published

2026-05-05

·

Updated

2026-05-08

·

CVE-2026-38432

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ERPNext versions prior to 15.103.2
Description The Email Template engine allows an attacker with permissions to create or edit email templates to inject malicious JavaScript code. This code is executed in the victim's browser when the template is applied. Cross Site Scripting (XSS) is a flaw where malicious scripts are injected into otherwise trusted websites.
Recommendations Update to a version newer than 15.103.1.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-38432

Affected Products

Erpnext