Loading
Generated remediation guidance and an executive summary. No account required.
Frappe is a full-stack web application framework. Prior to 14.100.2, 15.101.0, and 16.10.0, due to a lack of validation and improper permission checks, users could modify other user's private workspaces. Specially crafted requests could lead to stored XSS here. This vulnerability is fixed in 14.100.2, 15.101.0, and 16.10.0.
No affected products information available.
Cite this page
CVE-2026-31879. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-31879
Use CWE-79 to widen CVE-2026-31879 into its surrounding weakness, vendor, and product context.