Junglewise Threat Intelligence

CVE-2026-50711: Frappe Framework Stored XSS in Number Card component

CVE-2026-50711 · Severity: info · CVSS 4.6 · Published 2026-06-24

Vendors: Frappe.

Executive brief

Frappe Framework is a low-code web framework used to build business applications. A security vulnerability in its 'Number Card' component allows an attacker with high-level privileges to inject malicious scripts into the system. If another user views the affected component, these scripts could execute in their browser, potentially leading to unauthorized actions or data access within the application.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Frappe Framework 17.0.0-dev. The flaw is located in the Number Card component, specifically within the rendering of filter fields, where user-controlled input is not properly neutralized. An attacker with high privileges (PR:H) can inject malicious JavaScript that is stored on the server. The payload executes when an administrative user interacts with the affected component (UI:A). This can lead to a limited impact on the integrity and confidentiality of the user's session within the web application.

Affected products

  • Frappe Frappe Framework 17.0.0-dev

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory

References