Vulnerability Description
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and earlier, there is a stored XSS vulnerability where a specially crafted image filename could execute malicious JavaScript when rendered on course or jobs pages.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Frappe | Learning | >= 2.0.0, < 2.45.0 |
Related Weaknesses (CWE)
References
- https://github.com/frappe/lms/commit/e7ccf0a711d0e0ab5e6b28b7a1e4e0510b6b9543Patch
- https://github.com/frappe/lms/security/advisories/GHSA-78mq-3whw-69j5Third Party Advisory
FAQ
What is CVE-2026-23497?
CVE-2026-23497 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and earlier, there is a stored XSS vulnerability where a specially crafted image filena...
How severe is CVE-2026-23497?
CVE-2026-23497 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-23497?
Check the references section above for vendor advisories and patch information. Affected products include: Frappe Learning.