{"id":"CVE-2025-68928","title":"Frappe CRM is an open-source customer relationship management tool","summary":"Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could set crafted URLs in a website field, which were not sanitized, causing cross-site scripting. Version 1.56.2 fixes the …","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"frappe","product":"frappe_crm","affected":["frappe_crm < 1.56.2"],"patched":["frappe_crm 1.56.2"],"published":"2025-12-29","updated":"2026-10-05","sourceUpdated":"2026-10-05T19:10:00.210","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-68928","references":[{"url":"https://github.com/frappe/crm/commit/c5766d9989131d17d954e866bfc4b8d3b23e4f10","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/crm/releases/tag/v1.56.2","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/crm/security/advisories/GHSA-fm34-v6j7-chwc","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00206,"epssPercentile":0.09637,"ingestedAt":"2026-10-05T19:30:59.954Z","slug":"CVE-2025-68928","body":"## Overview\n\nFrappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could set crafted URLs in a website field, which were not sanitized, causing cross-site scripting. Version 1.56.2 fixes the issue. No known workarounds are available.\n\n## Affected\n\n- `frappe_crm < 1.56.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `frappe_crm 1.56.2`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}