By vendor
Frappe vulnerabilities
Known CVEs affecting Frappe products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-46546MEDIUM 5.4
Frappe Learning Management System prior to version 2.53.0 contains a vulnerability where authenticated users can inject malicious code into certain editable fields. When these fields are displayed in page metadata, visiting users' browsers are automatically redirected to attacker-controlled URLs without their knowledge. The vulnerability requires an attacker to have valid user credentials and for a victim to visit a page containing the injected content, but once triggered, it can lead to credential theft, malware distribution, or other social engineering attacks.