Fiche vulnérabilité
CVE-2026-34606 : faille moyenne frappe learning (CVSS 6.1)
Description
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, Frappe LMS was vulnerable to stored XSS. This issue has been patched in version 2.48.0.
En bref
- Sévérité
- Moyenne (CVSS 6.1)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 2 avr. 2026
- Dernière mise à jour
- 24 juil. 2026
Produits concernés
- frappe learning