This issue affects Frappe: 16.10.10.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 22 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where tags are rendered. The vulnerable renderer interpolates tag content into HTML attributes and element content without escaping. This issue affects Frappe: 16.10.10. | |
| Title | Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer | |
| First Time appeared |
Frappe
Frappe frappe |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:frappe:frappe:16.10.10:*:linux:*:*:*:*:* cpe:2.3:a:frappe:frappe:16.10.10:*:macos:*:*:*:*:* cpe:2.3:a:frappe:frappe:16.10.10:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Frappe
Frappe frappe |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-04-22T19:58:00.187Z
Reserved: 2026-03-06T21:12:23.365Z
Link: CVE-2026-3673
Updated: 2026-04-22T19:56:41.273Z
Status : Awaiting Analysis
Published: 2026-04-22T20:16:41.790
Modified: 2026-04-22T21:23:52.620
Link: CVE-2026-3673
No data.
OpenCVE Enrichment
Updated: 2026-04-22T21:30:27Z