CVE-2026-23497

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and earlier, there is a stored XSS vulnerability where a specially crafted image filename could execute malicious JavaScript when rendered on course or jobs pages.
Configurations

Configuration 1 (hide)

cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-14 19:16

Updated : 2026-01-16 18:44


NVD link : CVE-2026-23497

Mitre link : CVE-2026-23497

CVE.ORG link : CVE-2026-23497


JSON object : View

Products Affected

frappe

  • learning
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')