A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1 when using the Update Existing Recordsoption. An attacker can embed malicious JavaScript code into a CSV field, which is then stored in the database and executed whenever the affected record is viewed by a user within the ERPNext web interface. This exposure may allow an attacker to compromise user sessions or perform unauthorized actions under the context of a victim's account.
Cite this page
CVE-2025-65923. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-65923
Use CWE-79, Frappe vendor hub and Erpnext product page to widen CVE-2025-65923 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-67289, CVE-2026-27471 and CVE-2026-31017 for nearby disclosures in the same product family.