VYPR
High severity7.5NVD Advisory· Published Aug 20, 2025· Updated Jun 17, 2026

CVE-2025-55732

CVE-2025-55732

Description

Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass of the official patch released for CVE-2025-52895. This vulnerability is fixed in 15.74.2 and 14.96.15.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Frappe/Frappe3 versions
    cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*range: <14.96.15
    • (no CPE)range: <15.74.2, <14.96.15
    • (no CPE)range: >= 15.0.0, < 15.74.2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.