Frappe
by Frappe
Source repositories
CVEs (98)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-55732 | Hig | 0.00 | 7.5 | 0.00 | Aug 20, 2025 | Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass of the official patch released… | ||
| CVE-2025-55731 | Hig | 0.00 | 8.8 | 0.00 | Aug 20, 2025 | Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15. | ||
| CVE-2025-52898 | Hig | 0.00 | 8.8 | 0.00 | Jun 30, 2025 | Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting access to a user's password reset token. This can only be exploited on self hosted instances configured in a certain way.… | ||
| CVE-2025-52896 | Med | 0.00 | 5.4 | 0.00 | Jun 30, 2025 | Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading to cross-site scripting (XSS). This issue has been patched in versions 14.94.2 and 15.57.0. There… | ||
| CVE-2025-52895 | Hig | 0.00 | 7.5 | 0.00 | Jun 30, 2025 | Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted request, which could allow malicious person to gain access to sensitive information. This issue has been patched in versions 14.94.3… | ||
| CVE-2024-34074 | Med | 0.00 | 6.1 | 0.01 | May 14, 2024 | Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerability is fixed in 15.26.0 and… | ||
| CVE-2023-5555 | Med | 0.00 | 6.1 | 0.00 | Oct 12, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository frappe/lms prior to 5614a6203fb7d438be8e2b1e3030e4528d170ec4. | ||
| CVE-2022-3988 | Low | 0.00 | 3.5 | 0.01 | Nov 14, 2022 | A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functionality of the file frappe/templates/includes/navbar/navbar_search.html of the component Search. The manipulation of the argument q leads to cross site scripting.… | ||
| CVE-2022-23055 | 0.00 | — | 0.01 | Jun 22, 2022 | In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker… | |||
| CVE-2022-23058 | 0.00 | — | 0.01 | Jun 22, 2022 | ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover. | |||
| CVE-2022-23057 | Med | 0.00 | 5.4 | 0.01 | Jun 22, 2022 | In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile. | ||
| CVE-2020-35175 | Med | 0.00 | 5.3 | 0.01 | Dec 11, 2020 | Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API. | ||
| CVE-2020-27508 | Hig | 0.00 | 7.5 | 0.01 | Dec 11, 2020 | In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security. | ||
| CVE-2019-20529 | Hig | 0.00 | 7.5 | 0.01 | Mar 18, 2020 | In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files. | ||
| CVE-2019-15700 | Med | 0.00 | 6.1 | 0.01 | Aug 27, 2019 | public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text. | ||
| CVE-2019-14967 | Med | 0.00 | 6.1 | 0.01 | Aug 12, 2019 | An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability. | ||
| CVE-2019-14966 | Hig | 0.00 | 8.8 | 0.02 | Aug 12, 2019 | An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection. | ||
| CVE-2019-14965 | Cri | 0.00 | 9.8 | 0.03 | Aug 12, 2019 | An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists. |
- risk 0.00cvss 7.5epss 0.00
Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass of the official patch released…
- risk 0.00cvss 8.8epss 0.00
Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15.
- risk 0.00cvss 8.8epss 0.00
Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting access to a user's password reset token. This can only be exploited on self hosted instances configured in a certain way.…
- risk 0.00cvss 5.4epss 0.00
Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading to cross-site scripting (XSS). This issue has been patched in versions 14.94.2 and 15.57.0. There…
- risk 0.00cvss 7.5epss 0.00
Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted request, which could allow malicious person to gain access to sensitive information. This issue has been patched in versions 14.94.3…
- risk 0.00cvss 6.1epss 0.01
Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerability is fixed in 15.26.0 and…
- risk 0.00cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Generic in GitHub repository frappe/lms prior to 5614a6203fb7d438be8e2b1e3030e4528d170ec4.
- risk 0.00cvss 3.5epss 0.01
A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functionality of the file frappe/templates/includes/navbar/navbar_search.html of the component Search. The manipulation of the argument q leads to cross site scripting.…
- CVE-2022-23055Jun 22, 2022risk 0.00cvss —epss 0.01
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker…
- CVE-2022-23058Jun 22, 2022risk 0.00cvss —epss 0.01
ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.
- risk 0.00cvss 5.4epss 0.01
In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.
- risk 0.00cvss 5.3epss 0.01
Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.
- risk 0.00cvss 7.5epss 0.01
In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security.
- risk 0.00cvss 7.5epss 0.01
In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files.
- risk 0.00cvss 6.1epss 0.01
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.
- risk 0.00cvss 6.1epss 0.01
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
- risk 0.00cvss 8.8epss 0.02
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.
- risk 0.00cvss 9.8epss 0.03
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.
Page 5 of 5