VYPR
Medium severity6.1NVD Advisory· Published May 5, 2026· Updated May 8, 2026

CVE-2026-38432

CVE-2026-38432

Description

ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when the template is applied.

Affected products

2
  • Frappe/Erpnext2 versions
    cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*range: <=15.103.1
    • (no CPE)range: <=15.103.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.