CVE-2026-34606

Source
https://cve.org/CVERecord?id=CVE-2026-34606
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34606.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-34606
Aliases
  • GHSA-qf5w-r34q-c7j2
Published
2026-04-02T17:50:01.153Z
Modified
2026-08-12T03:51:14.520002509Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Stored XSS in Frappe LMS
Details

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, Frappe LMS was vulnerable to stored XSS. This issue has been patched in version 2.48.0.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34606.json"
}
References

Affected packages

Git / github.com/frappe/lms

Affected ranges

Type
GIT
Repo
https://github.com/frappe/lms
Events
Database specific
Show details
{
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.27.0"
        },
        {
            "fixed": "2.48.0"
        }
    ]
}

Affected versions

v2.*
v2.27.0
v2.28.0
v2.28.1
v2.29.0
v2.30.0
v2.31.0
v2.32.0
v2.32.1
v2.32.2
v2.33.0
v2.34.1
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.39.0
v2.39.1
v2.39.2
v2.40.0
v2.41.0
v2.42.0
v2.43.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34606.json"