CVE-2026-50709EPSS p32.5%
CVE-2026-50709CVE-2026-50709
Description
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.
Scoring
| EPSS | 0.40% probability of exploitation · percentile 32.5% · 2026-10-06T12:00:23Z |
| Last modified | 2026-06-25 |