VYPR
Medium severityNVD Advisory· Published Jun 24, 2026· Updated Jun 25, 2026

CVE-2026-50709

CVE-2026-50709

Description

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

1