VYPR

Frappe

by Frappe

pypi: frappe

Source repositories

CVEs (108)

  • CVE-2026-28436HigMar 5, 2026
    risk 0.47cvss 7.2epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted image URL that results in XSS when the avatar is displayed, and it can be triggered for other users via website page comments. This issue has been patched in…

  • CVE-2026-47765HigAug 6, 2026
    risk 0.46cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, allowing an authenticated user to restore deleted documents without the required authorization. This…

  • CVE-2026-29077HigMar 5, 2026
    risk 0.46cvss 7.1epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation when sharing documents, a user could share a document with a permission that they themselves didn't have. This issue has been patched in versions 15.98.0 and…

  • CVE-2025-58375HigSep 6, 2025
    risk 0.46cvss 8.1epss 0.00

    Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved.…

  • CVE-2025-66206MedDec 1, 2025
    risk 0.44cvss 6.8epss 0.00

    Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path traversal attacks, wherein some files from the server could be retrieved if the full path was known. Sites hosted on Frappe Cloud, and even other setups that…

  • CVE-2026-29081MedMar 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This issue has been patched in…

  • CVE-2025-56381MedOct 2, 2025
    risk 0.42cvss 6.5epss 0.00

    ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the order_by and group_by parameters.

  • CVE-2025-56380MedOct 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endpoint and a crafted script to the fieldname parameter

  • CVE-2025-52048MedSep 15, 2025
    risk 0.42cvss 6.5epss 0.00

    In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py` is vulnerable to SQL Injection, which allows an attacker to extract information from databases by injecting a SQL query into the `dt` parameter.

  • CVE-2025-30212HigMar 25, 2025
    risk 0.42cvss 7.5epss 0.00

    Frappe is a full-stack web application framework. An SQL Injection vulnerability has been identified in Frappe Framework prior to versions 14.89.0 and 15.51.0 which could allow a malicious actor to access sensitive information. Versions 14.89.0 and 15.51.0 fix the issue.…

  • CVE-2022-41712MedNov 25, 2022
    risk 0.42cvss 6.5epss 0.01

    Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correctly validate the information injected by the user in the import_file parameter.

  • CVE-2025-62407MedOct 16, 2025
    risk 0.40cvss 6.1epss 0.00

    Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the login page, if a specific type of URL was passed in. This vulnerability is fixed in 14.98.0 and 15.83.0.

  • CVE-2026-66003HigAug 26, 2026
    risk 0.39cvss —epss 0.00

    Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access control bypass in the REST API allows a user to read data from Linked DocTypes that they are not authorized to access. When a document references another…

  • CVE-2026-62315HigAug 20, 2026
    risk 0.39cvss —epss 0.00

    Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py checks a dictionary supplied through the fieldname parameter against forbidden standard and child-table fields before parsing the dictionary into…

  • CVE-2026-66002MedAug 20, 2026
    risk 0.38cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return distinguishable response…

  • CVE-2026-63654MedAug 20, 2026
    risk 0.38cvss —epss 0.00

    Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow approvals because the endpoint is not…

  • CVE-2026-53568MedJun 12, 2026
    risk 0.38cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerablity in Frappe Report/List View. This issue has been patched in versions 15.107.2 and 16.17.4.

  • CVE-2026-50026MedJun 12, 2026
    risk 0.38cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in these endpoints allowed unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.17.0.

  • CVE-2026-44208MedJun 12, 2026
    risk 0.38cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint allows for unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.17.0.

  • CVE-2026-44207MedJun 12, 2026
    risk 0.38cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access other users' email configuration details. This issue has been patched in versions 15.107.0 and 16.17.0.

Page 2 of 6