|
1601
|
- |
|
-
|
-
|
A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component.
|
CWE-79
Cross-site Scripting
|
CVE-2026-50701
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1602
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer.
|
CWE-79
Cross-site Scripting
|
CVE-2026-50703
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1603
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer.
|
CWE-79
Cross-site Scripting
|
CVE-2026-50704
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1604
|
- |
|
-
|
-
|
A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer.
|
CWE-79
Cross-site Scripting
|
CVE-2026-50705
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1605
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component.
|
CWE-79
Cross-site Scripting
|
CVE-2026-50708
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1606
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.
|
CWE-79
Cross-site Scripting
|
CVE-2026-50709
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1607
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.
|
CWE-79
Cross-site Scripting
|
CVE-2026-50710
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1608
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component.
|
CWE-79
Cross-site Scripting
|
CVE-2026-50711
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1609
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component
|
CWE-79
Cross-site Scripting
|
CVE-2026-50712
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1610
|
8.7 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without v…
|
CWE-287
Improper Authentication
|
CVE-2026-56223
|
2026-06-25 23:03 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|