216.73.217.22

CVE-2026-3837

· Published 22/04/2026 21:17 · Modified 22/04/2026 21:23

Labels: CVE-2026-3837 2026-04-22CVE-2026-3837CWE-79[email protected]

Essential information

Published
22/04/2026 21:17
Modified
22/04/2026 21:23
Author
Creator
CVSS
4.6 MEDIUM (v3) 4.6 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the affected document in Desk. The vulnerable formatter implementations interpolate stored values into raw HTML attributes and element content without escaping This issue affects Frappe: 16.10.0.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
frappe / frappe cpe:2.3:a:frappe:frappe:16.10.0:*:*:*:*:*:*:*

References