CVE-2026-23497: Frappe Learning
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and earlier, there is a stored XSS vulnerability where a specially crafted image filename could execute malicious JavaScript when rendered on course or jobs pages.
Affected products
- Frappe Learning: from 2.0.0, before 2.45.0 (fixed in 2.45.0)
Published 2026-01-14. Last modified 2026-06-17.