CVE-2025-67734Medium· 5.4▾ SunlitFrappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allowed authenticated attackers to enter JavaScript through the Company Website field of the Job Form, exposi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allowed authenticated attackers to enter JavaScript through the Company Website field of the Job Form, exposing users to an XSS attack. The script could then be executed in the browsers of users who opened the malicious job posting. This issue is fixed in version 2.42.0.
learning >= 2.0.0, < 2.42.0Upgrade past the affected range:
learning 2.42.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-67730Medium· 5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content
CVE-2025-68928Medium· 5.4Frappe CRM is an open-source customer relationship management tool
CVE-2025-66581Medium· 6.5Frappe Learning Management System (LMS) is a learning system that helps users structure their content
CVE-2026-81731Medium· 5.4Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description
CVE-2023-51769Medium· 6.1Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
CVE-2022-28598Medium· 6.1Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.