CVE-2025-52896
Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could uploa
Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading to cross-site scripting (XSS). This issue has been patched in versions 14.94.2 and 15.57.0.
There are no workarounds for this issue other than upgrading.
MEDIUM · CVSS 5.4
EPSS 0.00175
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules0
YARA rules0