CVE-2026-38432: Frappe Erpnext

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when the template is applied.

Affected products

  • Frappe Erpnext: up to and including 15.103.1

Published 2026-05-05. Last modified 2026-07-24.