CVE-2026-28436: Frappe: Stored XSS in avatar_macro.html
Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted image URL that results in XSS when the avatar is displayed, and it can be triggered for other users via website page comments. This issue has been patched in versions 16.11.0 and 15.102.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28436?
CVE-2026-28436 is classified as a high severity vulnerability due to its potential to enable stored cross-site scripting (XSS) attacks.
How do I fix CVE-2026-28436?
To fix CVE-2026-28436, upgrade to Frappe versions 16.11.0 or 15.102.0 or later.
What is the impact of CVE-2026-28436?
The impact of CVE-2026-28436 allows attackers to inject malicious scripts through crafted image URLs, affecting other users when displayed.
In which versions of Frappe is CVE-2026-28436 present?
CVE-2026-28436 is present in Frappe versions prior to 16.11.0 and 15.102.0.
How can CVE-2026-28436 be exploited?
CVE-2026-28436 can be exploited by an attacker who posts a comment containing a malicious image URL, which triggers XSS when viewed by other users.