Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-3673

An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where tags are rendered. The vulnerable renderer interpolates tag content into HTML attributes and element content without escaping. This issue affects Frappe: 16.10.10.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 11.6%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2026-3673
  • Frappe » Frappe » Version: 16.10.10
    cpe:2.3:a:frappe:frappe:16.10.10


Contact Us

Shodan ® - All rights reserved