VYPR
High severity8.8NVD Advisory· Published Aug 20, 2025· Updated Jun 17, 2026

CVE-2025-55731

CVE-2025-55731

Description

Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Frappe/Frappe3 versions
    cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*range: <14.96.15
    • (no CPE)range: 15.74.2, 14.96.15
    • (no CPE)range: < 14.96.15

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.