|
971
|
- |
|
-
|
-
|
A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-50705
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
972
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-50708
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
973
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-50709
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
974
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-50710
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
975
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-50711
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
976
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-50712
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
977
|
8.7 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without v…
New
|
CWE-287
Improper Authentication
|
CVE-2026-56223
|
2026-06-25 23:03 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
978
|
8.8 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewareKey function. Attackers can bypass subkey scope res…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-56232
|
2026-06-25 23:03 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
979
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are exposed in frontend requests, and the backend fails to validate that keys are se…
New
|
CWE-287
Improper Authentication
|
CVE-2026-56237
|
2026-06-25 23:03 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
980
|
7.1 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-level security policies on the webhooks table. Attackers can retrieve the web…
New
|
CWE-200
Information Exposure
|
CVE-2026-56244
|
2026-06-25 23:03 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|