CVE-2025-67730Medium· 5.4▾ TwilightPoC availableFrappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allow authenticated users to add malicious HTML and JavaScript through description fields in the Job, Course …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.7 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
1 GitHub repo (last check)
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allow authenticated users to add malicious HTML and JavaScript through description fields in the Job, Course and Batch forms. This issue is fixed in version 2.42.0.
learning >= 2.0.0, < 2.42.0Upgrade past the affected range:
learning 2.42.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-67734Medium· 5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content
CVE-2022-28598Medium· 6.1Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2025-68928Medium· 5.4Frappe CRM is an open-source customer relationship management tool
CVE-2025-66581Medium· 6.5Frappe Learning Management System (LMS) is a learning system that helps users structure their content
CVE-2026-81731Medium· 5.4Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description
CVE-2023-51769Medium· 6.1Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.