CVE-2026-50698: Frappe Framework 17.0.0-dev - Stored XSS in Audit Trail template rendering
Published Jun 24, 2026
·Updated
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HTML output in the Audit Trail component.
Affected Software
1 affected component
Frappe Frappe Framework=17.0.0-dev
Event History
Jun 24, 2026
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-50698?
CVE-2026-50698 has a risk score of 43, indicating a moderate severity level.
2
How do I fix CVE-2026-50698?
To mitigate CVE-2026-50698, update to a newer version of Frappe Framework where the Stored XSS vulnerability has been addressed.
3
What components are affected by CVE-2026-50698?
CVE-2026-50698 specifically affects the Audit Trail component of Frappe Framework version 17.0.0-dev.
4
What type of vulnerability is CVE-2026-50698?
CVE-2026-50698 is a Stored Cross-Site Scripting (XSS) vulnerability.
5
When was CVE-2026-50698 published?
CVE-2026-50698 was published on June 24, 2026.