ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when the template is applied.
History

Fri, 08 May 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Frappe
Frappe erpnext
CPEs cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*
Vendors & Products Frappe
Frappe erpnext

Wed, 06 May 2026 18:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Vulnerability in ERPNext Email Template Engine (v15.103.1 and Earlier)

Wed, 06 May 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 05 May 2026 20:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Vulnerability in ERPNext Email Template Engine (v15.103.1 and Earlier)
Weaknesses CWE-79

Tue, 05 May 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Erpnext
Erpnext erpnext
Vendors & Products Erpnext
Erpnext erpnext

Tue, 05 May 2026 17:00:00 +0000

Type Values Removed Values Added
Description ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when the template is applied.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-06T15:26:13.689Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-38432

cve-icon Vulnrichment

Updated: 2026-05-06T13:27:09.207Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-05T17:17:04.800

Modified: 2026-05-08T17:05:35.567

Link: CVE-2026-38432

cve-icon Redhat

No data.