VYPR

Frappe

by Frappe

pypi: frappe

Source repositories

CVEs (108)

  • CVE-2026-44206MedJun 12, 2026
    risk 0.38cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possible through exploiting an endpoint. This issue has been patched in versions 15.107.2 and 16.17.4.

  • CVE-2026-47739MedJun 12, 2026
    risk 0.38cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possible due to lack of sanitization. This issue has been patched in versions 15.106.0 and 16.16.0.

  • CVE-2026-44205MedJun 12, 2026
    risk 0.38cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user profile image section allows an attacker to execute malicious scripts in the browsers of other users. This issue has been patched in version 15.106.0.

  • CVE-2026-41581MedJun 12, 2026
    risk 0.38cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Injection via get_blog_list. This issue has been patched in versions 15.106.0 and 16.16.0.

  • CVE-2026-82634MedAug 30, 2026
    risk 0.35cvss 6.5epss 0.00

    Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates by supplying raw template strings. Attackers with print permission on any document can execute arbitrary…

  • CVE-2026-3673MedApr 22, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where tags are rendered. The vulnerable renderer interpolates tag content into HTML attributes and element content without escaping.…

  • CVE-2026-31879MedMar 11, 2026
    risk 0.35cvss 5.4epss 0.00

    Frappe is a full-stack web application framework. Prior to 14.100.2, 15.101.0, and 16.10.0, due to a lack of validation and improper permission checks, users could modify other user's private workspaces. Specially crafted requests could lead to stored XSS here. This…

  • CVE-2025-56379MedOct 2, 2025
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.

  • CVE-2024-24812MedFeb 7, 2024
    risk 0.35cvss 5.4epss 0.00

    Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and a tightly integrated client side library. Prior to versions 14.59.0 and 15.5.0, portal pages are susceptible to Cross-Site Scripting (XSS) which can be used to inject malicious…

  • CVE-2023-51769MedSep 14, 2026
    risk 0.33cvss 6.1epss 0.00

    Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.

  • CVE-2026-49391MedAug 6, 2026
    risk 0.33cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering previews and results, allowing an authenticated importer to persist script content that executes when another user views the…

  • CVE-2026-47185MedAug 6, 2026
    risk 0.33cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing workspace ownership, allowing modification of another user's private workspace and persistent script…

  • CVE-2026-50701MedJun 24, 2026
    risk 0.33cvss —epss 0.00

    A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component.

  • CVE-2026-31878MedMar 11, 2026
    risk 0.33cvss 5.0epss 0.00

    Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a crafted request to an endpoint which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in 14.100.1,…

  • CVE-2025-11281MedOct 5, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished Course Handler. Such manipulation leads to improper access controls. The attack may be launched remotely. This attack is…

  • CVE-2026-50712MedJun 24, 2026
    risk 0.31cvss —epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component

  • CVE-2026-50709MedJun 24, 2026
    risk 0.31cvss —epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.

  • CVE-2026-50708MedJun 24, 2026
    risk 0.31cvss —epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component.

  • CVE-2026-50703MedJun 24, 2026
    risk 0.31cvss —epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer.

  • CVE-2026-50711MedJun 24, 2026
    risk 0.30cvss —epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component.

Page 3 of 6