PT-2026-46043 · Frappe · Erpnext

Oscar Naveda

·

Published

2026-06-03

·

Updated

2026-06-03

·

CVE-2026-42839

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item name, description, or image fields of an Item and trigger unescaped rendering in the Point of Sale (POS) cart interface for every operator who adds that item to a transaction.This issue affects ERPNext: 16.16.0.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-42839

Affected Products

Erpnext