Frappe · Frappe Lms · CVE-2026-34606
**Name of the Vulnerable Software and Affected Versions**
Frappe Learning Management System (LMS) versions 2.27.0 through 2.47.9
**Description**
Frappe Learning Management System (LMS) is a system designed to help users structure content. The software contains a stored Cross-Site Scripting (XSS) flaw, which occurs when an application includes untrusted data in a web page without proper validation or encoding, allowing a malicious script to be permanently stored on the server and executed in the browser of other users.
**Recommendations**
Update to version 2.48.0.