Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allowed authenticated attackers to enter JavaScript through the Company Website field of the Job Form, exposing users to an XSS attack. The script could then be executed in the browsers of users who opened the malicious job posting. This issue is fixed in version 2.42.0.
Cite this page
CVE-2025-67734. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-67734
Use CWE-79, Frappe vendor hub and Learning product page to widen CVE-2025-67734 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-34606, CVE-2026-26977 and CVE-2026-39415 for nearby disclosures in the same product family.