CVE-2026-44205: Frappe: Stored Cross-Site Scripting (XSS) in User Profile through Image Upload
Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user profile image section allows an attacker to execute malicious scripts in the browsers of other users. This issue has been patched in version 15.106.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 15.106.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44205?
CVE-2026-44205 has a medium severity level with a CVSS score of 6.9.
How do I fix CVE-2026-44205?
To resolve CVE-2026-44205, upgrade to Frappe version 15.106.0 or later.
What type of vulnerability is CVE-2026-44205?
CVE-2026-44205 is a stored Cross-Site Scripting (XSS) vulnerability.
What can attackers achieve with CVE-2026-44205?
Attackers can execute malicious scripts in the browsers of other users through the user profile image upload feature.
When was CVE-2026-44205 published?
CVE-2026-44205 was published on June 12, 2026.