CVE-2025-56379: XSS
Published Oct 2, 2025
·Updated
A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.
Affected Software
3 affected components
ERPNext ERPNext
Frappe ERPNext=15.67.0
Frappe frappe=15.72.4
Event History
Oct 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56379?
CVE-2025-56379 has a high severity rating due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2025-56379?
To fix CVE-2025-56379, update to the latest version of ERPNEXT that addresses this XSS vulnerability.
3
What type of attack does CVE-2025-56379 enable?
CVE-2025-56379 enables attackers to execute arbitrary web scripts or HTML via crafted payloads in the blog post feature.
4
Which versions of ERPNEXT are affected by CVE-2025-56379?
CVE-2025-56379 specifically affects ERPNEXT version 15.67.0.
5
What components are involved in CVE-2025-56379?
CVE-2025-56379 involves the blog post feature of ERPNEXT where user content is not properly sanitized.