CVE-2026-25956 | Frappe up to 14.99.13/15.93.x Signup cross site scripting (GHSA-7m8v-g2pr-h2f7)
A vulnerability identified as problematic has been detected in Frappe up to 14.99.13/15.93.x. This issue affects some unknown processing of the component Signup. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-25956. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.