CVE-2025-68928: Frappe CRM vulnerable to authenticated XSS via website field
Published Dec 29, 2025
·Updated
Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could set crafted URLs in a website field, which were not sanitized, causing cross-site scripting. Version 1.56.2 fixes the issue. No known workarounds are available.
Affected Software
2 affected components
frappe/CRM<1.56.2
Frappe Frappe CRM<1.56.2
Remediation
Event History
Dec 29, 2025
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-68928?
CVE-2025-68928 has a critical severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2025-68928?
To fix CVE-2025-68928, upgrade to Frappe CRM version 1.56.2 or later.
3
What does CVE-2025-68928 affect?
CVE-2025-68928 affects Frappe CRM versions prior to 1.56.2.
4
Can authenticated users exploit CVE-2025-68928?
Yes, authenticated users can exploit CVE-2025-68928 by setting crafted URLs in website fields.
5
Are there any workarounds for CVE-2025-68928?
No known workarounds are available for CVE-2025-68928; upgrading is the only solution.