VYPR

Frappe

by Frappe

pypi: frappe

Source repositories

CVEs (98)

  • CVE-2026-44976MedJun 12, 2026
    risk 0.27cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue has been patched in version 16.17.4.

  • CVE-2026-44975MedJun 12, 2026
    risk 0.27cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users in the system. This issue has been patched in versions 15.107.2 and 16.17.4.

  • CVE-2023-41328MedSep 6, 2023
    risk 0.27cvss 4.2epss 0.00

    Frappe is a low code web framework written in Python and Javascript. A SQL Injection vulnerability has been identified in the Frappe Framework which could allow a malicious actor to access sensitive information. This issue has been addressed in versions 13.46.1 and 14.20.0.…

  • CVE-2025-11280LowOct 5, 2025
    risk 0.24cvss 3.7epss 0.00

    A flaw has been found in Frappe LMS 2.35.0. Impacted is an unknown function of the file /files/ of the component Assignment Picture Handler. This manipulation causes direct request. The attack may be initiated remotely. The attack's complexity is rated as high. The…

  • CVE-2025-11283LowOct 5, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. Executing manipulation of the argument Description can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly…

  • CVE-2026-66000LowAug 7, 2026
    risk 0.08cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by…

  • CVE-2023-46127MedOct 23, 2023
    risk 0.03cvss 5.4epss 0.37

    Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vulnerability has been…

  • CVE-2026-12895HigJul 29, 2026
    risk 0.00cvss epss 0.00

    SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing parameterized queries, allowing the name (docname) of a Supplier record containing…

  • CVE-2026-58503MedJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.

  • CVE-2026-55852HigJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tarfile members were not sufficiently checked before extraction. This issue is fixed in versions 16.23.0 and 15.112.0.

  • CVE-2026-49394HigJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed in version 16.19.0.

  • CVE-2026-48127MedJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints such as add_attachments. This issue is fixed in versions 16.20.0 and 15.110.0.

  • CVE-2026-47422MedJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2.

  • CVE-2026-47199LowJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT INTO OUTFILE queries, which could potentially work on self-hosted sites if database permissions are not well aligned and MySQL FILE privileges are available.…

  • CVE-2026-42219MedJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was possible due to lack of hardening. This issue is fixed in versions 16.19.0 and 15.109.0.

  • CVE-2026-41482HigJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion were possible through secure local resource access in the Chrome PDF Generator. This issue is fixed in version 16.18.3.

  • CVE-2026-25956MedFeb 10, 2026
    risk 0.00cvss 6.1epss 0.00

    Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious signup URL for a frappe site which could lead to an open redirect (or reflected XSS, depending on the crafted payload) when a user signs up. This vulnerability is…

  • CVE-2025-68953HigJan 5, 2026
    risk 0.00cvss 7.5epss 0.00

    Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests that are vulnerable to path traversal attacks. Arbitrary files from the server could be retrieved due to a lack of proper sanitization on some requests. This…

  • CVE-2025-66205HigDec 1, 2025
    risk 0.00cvss 7.1epss 0.00

    Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to lack of validation of parameters. Some information like version could be retrieved. This vulnerability is fixed in 15.86.0 and…

  • CVE-2025-11461HigNov 26, 2025
    risk 0.00cvss 8.8epss 0.00

    Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. This issue affects Frappe CRM: 1.53.1.

Page 4 of 5