NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-3837
Summary

An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the affected document in Desk. The vulnerable formatter implementations interpolate stored values into raw HTML attributes and element content without escaping

This issue affects Frappe: 16.10.0.

Publication Date April 23, 2026, 6:17 a.m.
Registration Date April 25, 2026, 4:06 a.m.
Last Update April 23, 2026, 6:23 a.m.
Related information, measures and tools
Common Vulnerabilities List