
CVE-2025-65924 ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are intended for plain text. Although JavaScript is bl… https://www.cve.org/CVERecord?id=CVE-2025-65924
Post summary
ERPNext versions up to 15.88.1 do not sanitize <a> tags in plain‑text fields, exposing a potential XSS vulnerability.
