VYPR
Unrated severityNVD Advisory· Published Aug 20, 2025· Updated Aug 20, 2025

Frappe has the possibility of SQL Injection due to improper validations

CVE-2025-55732

Description

Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass of the official patch released for CVE-2025-52895. This vulnerability is fixed in 15.74.2 and 14.96.15.

Affected products

2
  • Frappe/Frappellm-fuzzy2 versions
    <15.74.2 and <14.96.15+ 1 more
    • (no CPE)range: <15.74.2 and <14.96.15
    • (no CPE)range: >= 15.0.0, < 15.74.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.