Unrated severityNVD Advisory· Published Aug 20, 2025· Updated Aug 20, 2025
Frappe has the possibility of SQL Injection due to improper validations
CVE-2025-55732
Description
Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass of the official patch released for CVE-2025-52895. This vulnerability is fixed in 15.74.2 and 14.96.15.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/frappe/frappe/commit/24dd2d9420a7c68ce09875cb18586d1bf071c857mitrex_refsource_MISC
- github.com/frappe/frappe/commit/abe2cc25e333cd794405d12caec4da0279a54e6emitrex_refsource_MISC
- github.com/frappe/frappe/security/advisories/GHSA-6rpr-2hjx-w9vpmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.