VYPR

Frappe

by Frappe

pypi: frappe

Source repositories

CVEs (98)

  • CVE-2025-55732HigAug 20, 2025
    risk 0.00cvss 7.5epss 0.00

    Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass of the official patch released…

  • CVE-2025-55731HigAug 20, 2025
    risk 0.00cvss 8.8epss 0.00

    Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15.

  • CVE-2025-52898HigJun 30, 2025
    risk 0.00cvss 8.8epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting access to a user's password reset token. This can only be exploited on self hosted instances configured in a certain way.…

  • CVE-2025-52896MedJun 30, 2025
    risk 0.00cvss 5.4epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading to cross-site scripting (XSS). This issue has been patched in versions 14.94.2 and 15.57.0. There…

  • CVE-2025-52895HigJun 30, 2025
    risk 0.00cvss 7.5epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted request, which could allow malicious person to gain access to sensitive information. This issue has been patched in versions 14.94.3…

  • CVE-2024-34074MedMay 14, 2024
    risk 0.00cvss 6.1epss 0.01

    Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerability is fixed in 15.26.0 and…

  • CVE-2023-5555MedOct 12, 2023
    risk 0.00cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Generic in GitHub repository frappe/lms prior to 5614a6203fb7d438be8e2b1e3030e4528d170ec4.

  • CVE-2022-3988LowNov 14, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functionality of the file frappe/templates/includes/navbar/navbar_search.html of the component Search. The manipulation of the argument q leads to cross site scripting.…

  • CVE-2022-23055Jun 22, 2022
    risk 0.00cvss epss 0.01

    In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker…

  • CVE-2022-23058Jun 22, 2022
    risk 0.00cvss epss 0.01

    ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.

  • CVE-2022-23057MedJun 22, 2022
    risk 0.00cvss 5.4epss 0.01

    In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.

  • CVE-2020-35175MedDec 11, 2020
    risk 0.00cvss 5.3epss 0.01

    Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

  • CVE-2020-27508HigDec 11, 2020
    risk 0.00cvss 7.5epss 0.01

    In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security.

  • CVE-2019-20529HigMar 18, 2020
    risk 0.00cvss 7.5epss 0.01

    In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files.

  • CVE-2019-15700MedAug 27, 2019
    risk 0.00cvss 6.1epss 0.01

    public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.

  • CVE-2019-14967MedAug 12, 2019
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.

  • CVE-2019-14966HigAug 12, 2019
    risk 0.00cvss 8.8epss 0.02

    An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.

  • CVE-2019-14965CriAug 12, 2019
    risk 0.00cvss 9.8epss 0.03

    An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.

Page 5 of 5