Frappe CRM Cross-Site Scripting Vulnerability in Website Field

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Frappe CRM versions prior to 1.56.2. The issue allows authenticated users to inject crafted URLs into a website field, which are not properly sanitized, leading to XSS. The vulnerability has been patched in version 1.56.2.

Impact

Exploitation of this vulnerability allows for authenticated cross-site scripting, where injected scripts can be executed in the context of the user.

Remediation

Users are advised to upgrade to Frappe CRM version 1.56.2 or later.

Added: Dec 29, 2025, 3:23 PM
Updated: Dec 29, 2025, 4:00 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.7
remediation
7.7
relevance
1.6
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.