Unrated severityNVD Advisory· Published Aug 20, 2025· Updated Aug 20, 2025
Frappe has the possibility of Authenticated SQL Injection due to improper validations
CVE-2025-55731
Description
Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/frappe/frappe/commit/93ee30c638bf7a7e33e2937a0adccac14c38b410mitrex_refsource_MISC
- github.com/frappe/frappe/commit/c2b01e3eb6f50e9bd05df0440f5cbf5dfbc1baddmitrex_refsource_MISC
- github.com/frappe/frappe/security/advisories/GHSA-5p8f-568f-vfq2mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.