CVE-2026-50709EPSS p15.1%
CVE-2026-50709CVE-2026-50709
Description
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.
Scoring
| EPSS | 0.24% probability of exploitation · percentile 15.1% · 2026-08-11T12:00:17Z |
| Last modified | 2026-06-25 |