Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-50704

Publication date:
24/06/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer.
Severity CVSS v4.0: MEDIUM
Last modification:
25/06/2026

CVE-2026-50705

Publication date:
24/06/2026
A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer.
Severity CVSS v4.0: MEDIUM
Last modification:
25/06/2026

CVE-2026-50708

Publication date:
24/06/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component.
Severity CVSS v4.0: MEDIUM
Last modification:
25/06/2026

CVE-2026-50709

Publication date:
24/06/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.
Severity CVSS v4.0: MEDIUM
Last modification:
25/06/2026

CVE-2026-50710

Publication date:
24/06/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.
Severity CVSS v4.0: MEDIUM
Last modification:
25/06/2026

CVE-2026-50711

Publication date:
24/06/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component.
Severity CVSS v4.0: MEDIUM
Last modification:
25/06/2026

CVE-2026-50712

Publication date:
24/06/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component
Severity CVSS v4.0: MEDIUM
Last modification:
25/06/2026

CVE-2026-50700

Publication date:
24/06/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function.
Severity CVSS v4.0: MEDIUM
Last modification:
25/06/2026

CVE-2026-50699

Publication date:
24/06/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto Repeat form.
Severity CVSS v4.0: MEDIUM
Last modification:
25/06/2026

CVE-2026-50698

Publication date:
24/06/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HTML output in the Audit Trail component.
Severity CVSS v4.0: MEDIUM
Last modification:
25/06/2026

CVE-2026-11878

Publication date:
24/06/2026
Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS).<br /> <br /> This issue affects Access Manager: from 5.1 through 5.1.2.
Severity CVSS v4.0: HIGH
Last modification:
29/06/2026

CVE-2026-11877

Publication date:
24/06/2026
An unauthorized user can modify configuration through API<br /> calls that affects the OpenText Access<br /> Manager. This issue affects Access Manager before 5.1.3.
Severity CVSS v4.0: MEDIUM
Last modification:
29/06/2026