CVE-2026-38432 - ERPNext Cross Site Scripting (XSS) Vulnerability
CVE ID :CVE-2026-38432 Published : May 5, 2026, 5:17 p.m. | 1 hour, 37 minutes ago Description :ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript c
ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD
Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.
GET THE SUNDAY BRIEFING →RELATED · cyber
- [CYBER] Kelp claims that LayerZero approved the setup it blamed for $292 million bridge hack
- [CYBER] Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482)
- [CYBER] Why I spun my benchmark into its own repo (and why every dev tool with a benchmark should)
- [CYBER] I Built an AI Honeypot on GCP — Attackers Came in 4 Minutes
- [CYBER] Drift outlines a recovery plan for users after $295 million DPRK-linked exploit
- [CYBER] Google Will Pay $1.5 Million For Pixel Phone Security Exploit