Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

C0Wking

#18067of 56,330
15.9Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2026-37088
9.8
2026-05-05
Frappe · Erpnext · CVE-2026-38431
**Name of the Vulnerable Software and Affected Versions** ERPNext versions prior to 15.103.2 **Description** Server-Side Template Injection (SSTI) occurs when an attacker with permissions to create or edit email templates injects template expressions. These expressions are executed on the server during the template rendering process. **Recommendations** Update to a version later than 15.103.1.
PT-2026-37089
6.1
2026-05-05
Frappe · Erpnext · CVE-2026-38432
**Name of the Vulnerable Software and Affected Versions** ERPNext versions prior to 15.103.2 **Description** The Email Template engine allows an attacker with permissions to create or edit email templates to inject malicious JavaScript code. This code is executed in the victim's browser when the template is applied. Cross Site Scripting (XSS) is a flaw where malicious scripts are injected into otherwise trusted websites. **Recommendations** Update to a version newer than 15.103.1.