Vulnerability Description
ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when the template is applied.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Frappe | Erpnext | <= 15.103.1 |
Related Weaknesses (CWE)
References
- https://c0wking.hashnode.dev/stored-xss-in-erpnext-frappe-email-template-engineExploitThird Party Advisory
- https://c0wking.hashnode.dev/stored-xss-in-erpnext-frappe-email-template-engineExploitThird Party Advisory
FAQ
What is CVE-2026-38432?
CVE-2026-38432 is a vulnerability with a CVSS score of 6.1 (MEDIUM). ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript cod...
How severe is CVE-2026-38432?
CVE-2026-38432 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-38432?
Check the references section above for vendor advisories and patch information. Affected products include: Frappe Erpnext.