CVE-2026-42840 - ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals
CVE ID :CVE-2026-42840
Published : June 3, 2026, 7:16 p.m. | 1 hour, 46 minutes ago
Description :An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of Sale (POS) interface for every operator who selects that customer. This issue affects ERPNext: 16.16.0.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 3, 2026, 7:16 p.m. | 1 hour, 46 minutes ago
Description :An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of Sale (POS) interface for every operator who selects that customer. This issue affects ERPNext: 16.16.0.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...