VYPR
Critical severity9.8NVD Advisory· Published Mar 11, 2026· Updated Jun 17, 2026

CVE-2026-31877

CVE-2026-31877

Description

Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to. This vulnerability is fixed in 15.84.0 and 14.99.0.

Affected products

3
  • Frappe/Frappe3 versions
    cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*range: <14.99.0
    • (no CPE)range: <15.84.0, <14.99.0
    • (no CPE)range: >= 15.0.0, < 15.84.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.