VYPR
Medium severity6.1NVD Advisory· Published May 5, 2026· Updated May 8, 2026

CVE-2026-38432

CVE-2026-38432

Description

ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when the template is applied.

Affected products

2
  • Frappe/Erpnextinferred2 versions
    <=15.103.1+ 1 more
    • (no CPE)range: <=15.103.1
    • cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*range: <=15.103.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.