Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

Frappe: Unapproved images can harm users through website comments

CVE-2026-28436
Summary

An attacker can insert malicious images into website comments that can harm other users when displayed. This happened in Frappe before versions 16.11.0 and 15.102.0. Update to one of these patched versions to fix the issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
frappe frappe <= 15.102.0
frappe frappe > 16.0.0 , <= 16.11.0
Original title
Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted image URL that results in XSS when the avatar is displayed, and it can be tri...
Original description
Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted image URL that results in XSS when the avatar is displayed, and it can be triggered for other users via website page comments. This issue has been patched in versions 16.11.0 and 15.102.0.
nvd CVSS4.0 5.3
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 5 Mar 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026