VYPR
Unrated severityNVD Advisory· Published Aug 20, 2025· Updated Aug 20, 2025

Frappe has the possibility of Authenticated SQL Injection due to improper validations

CVE-2025-55731

Description

Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15.

Affected products

2
  • Frappe/Frappellm-fuzzy2 versions
    <=15.74.1, <=14.96.14+ 1 more
    • (no CPE)range: <=15.74.1, <=14.96.14
    • (no CPE)range: < 14.96.15

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.