---
id: CVE-2025-68928
title: Frappe CRM is an open-source customer relationship management tool
summary: >-
  Frappe CRM is an open-source customer relationship management tool. Prior to
  version 1.56.2, authenticated users could set crafted URLs in a website field,
  which were not sanitized, causing cross-site scripting. Version 1.56.2 fixes
  the …
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: frappe
product: frappe_crm
affected:
  - frappe_crm < 1.56.2
patched:
  - frappe_crm 1.56.2
published: '2025-12-29'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:10:00.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68928'
references:
  - url: >-
      https://github.com/frappe/crm/commit/c5766d9989131d17d954e866bfc4b8d3b23e4f10
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/crm/releases/tag/v1.56.2'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/crm/security/advisories/GHSA-fm34-v6j7-chwc'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00206
epssPercentile: 0.09637
ingestedAt: '2026-10-05T19:30:59.954Z'
---

## Overview

Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could set crafted URLs in a website field, which were not sanitized, causing cross-site scripting. Version 1.56.2 fixes the issue. No known workarounds are available.

## Affected

- `frappe_crm < 1.56.2`

## Remediation

Upgrade past the affected range:

- `frappe_crm 1.56.2`
