CVE-2023-51769: XSS
Published Sep 14, 2026
·Updated
Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
Affected Software
1 affected component
Frappe frappe<14.49.0
Event History
Sep 14, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Frappe versions before 14.49.0 are affected. The issue is associated with blog pages and exception pages.
2
What does exploitation require?
The vector is network-accessible, requires no attacker privileges, and has low attack complexity. A user must interact with the malicious content for exploitation to succeed.
3
What is the impact of a successful attack?
Successful cross-site scripting can result in limited confidentiality and integrity impact, with the impact scope extending beyond the vulnerable component.
4
How can this be remediated?
Upgrade Frappe to version 14.49.0 or later. The referenced comparison shows changes from 14.48.1 to 14.49.0.