Skip to content

Stored XSS in Frappe LMS

Moderate
raizasafeel published GHSA-qf5w-r34q-c7j2 Mar 31, 2026

Package

No package listed

Affected versions

>= 2.27.0, < 2.48.0

Patched versions

2.48.0

Description

Impact

Frappe LMS was vulnerable to stored XSS and Remote Code Execution in Lesson Content

Patches

The issue is fixed by preserving the sanitized HTML structure instead of extracting raw text.

Acknowledgement

Severity

Moderate

CVE ID

CVE-2026-34606

Weaknesses

No CWEs