VYPR

Frappe Framework

by Frappe

Source repositories

CVEs (19)

  • CVE-2025-67289CriDec 22, 2025
    risk 0.62cvss 9.6epss 0.00

    An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

  • CVE-2026-31017CriApr 8, 2026
    risk 0.59cvss 9.1epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When generating PDFs from user-controlled HTML…

  • CVE-2025-65267CriDec 3, 2025
    risk 0.59cvss 9.0epss 0.00

    In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting…

  • CVE-2025-56380MedOct 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endpoint and a crafted script to the fieldname parameter

  • CVE-2026-50701MedJun 24, 2026
    risk 0.33cvss epss 0.00

    A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component.

  • CVE-2026-50712MedJun 24, 2026
    risk 0.31cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component

  • CVE-2026-50709MedJun 24, 2026
    risk 0.31cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.

  • CVE-2026-50708MedJun 24, 2026
    risk 0.31cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component.

  • CVE-2026-50703MedJun 24, 2026
    risk 0.31cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer.

  • CVE-2026-50711MedJun 24, 2026
    risk 0.30cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component.

  • CVE-2026-50710MedJun 24, 2026
    risk 0.30cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.

  • CVE-2026-50705MedJun 24, 2026
    risk 0.30cvss epss 0.00

    A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer.

  • CVE-2026-50704MedJun 24, 2026
    risk 0.30cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer.

  • CVE-2026-50700MedJun 24, 2026
    risk 0.30cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function.

  • CVE-2026-50699MedJun 24, 2026
    risk 0.30cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users…

  • CVE-2026-50698MedJun 24, 2026
    risk 0.30cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HTML output in the Audit Trail component.

  • CVE-2025-52039HigOct 1, 2025
    risk 0.00cvss 8.2epss 0.00

    In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_request/material_request.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the…

  • CVE-2019-14967MedAug 12, 2019
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.

  • CVE-2019-14965CriAug 12, 2019
    risk 0.00cvss 9.8epss 0.03

    An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.