PT-2026-7328 · Frappe · Frappe
Stolichnayer
·
Published
2026-02-10
·
Updated
2026-02-10
·
CVE-2026-25956
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Frappe versions prior to 14.99.14
Frappe versions prior to 15.94.0
Description
A crafted malicious signup URL for a Frappe site could lead to an open redirect or reflected cross-site scripting (XSS), depending on the crafted payload, when a user signs up. The issue occurs when a user accesses a specially designed URL.
Recommendations
Update to Frappe version 14.99.14 or later.
Update to Frappe version 15.94.0 or later.
Exploit
Fix
Open Redirect
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Frappe