VYPR

Vendor CVEs

Frappe

All CVEs

195 total · sorted by risk
  • CVE-2025-52048MedSep 15, 2025
    risk 0.42cvss 6.5epss 0.00

    In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py` is vulnerable to SQL Injection, which allows an attacker to extract information from databases by injecting a SQL query into the `dt` parameter.

  • CVE-2025-30212HigMar 25, 2025
    risk 0.42cvss 7.5epss 0.00

    Frappe is a full-stack web application framework. An SQL Injection vulnerability has been identified in Frappe Framework prior to versions 14.89.0 and 15.51.0 which could allow a malicious actor to access sensitive information. Versions 14.89.0 and 15.51.0 fix the issue.…

  • CVE-2022-41712MedNov 25, 2022
    risk 0.42cvss 6.5epss 0.01

    Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correctly validate the information injected by the user in the import_file parameter.

  • CVE-2023-42807MedSep 21, 2023
    risk 0.41cvss 6.3epss 0.00

    Frappe LMS is an open source learning management system. In versions 1.0.0 and prior, on the People Page of LMS, there was an SQL Injection vulnerability. The issue has been fixed in the `main` branch. Users won't face this issue if they are using the latest main branch of the…

  • CVE-2026-38432MedMay 5, 2026
    risk 0.40cvss 6.1epss 0.00

    ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when the template is applied.

  • CVE-2025-62407MedOct 16, 2025
    risk 0.40cvss 6.1epss 0.00

    Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the login page, if a specific type of URL was passed in. This vulnerability is fixed in 14.98.0 and 15.83.0.

  • CVE-2019-20521MedMar 19, 2020
    risk 0.40cvss 6.1epss 0.01

    ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.

  • CVE-2019-20520MedMar 19, 2020
    risk 0.40cvss 6.1epss 0.01

    ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.

  • CVE-2019-20519MedMar 19, 2020
    risk 0.40cvss 6.1epss 0.01

    ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.

  • CVE-2019-20518MedMar 19, 2020
    risk 0.40cvss 6.1epss 0.01

    ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.

  • CVE-2019-20517MedMar 19, 2020
    risk 0.40cvss 6.1epss 0.01

    ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.

  • CVE-2019-20516MedMar 19, 2020
    risk 0.40cvss 6.1epss 0.01

    ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.

  • CVE-2019-20515MedMar 19, 2020
    risk 0.40cvss 6.1epss 0.01

    ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.

  • CVE-2019-20514MedMar 19, 2020
    risk 0.40cvss 6.1epss 0.01

    ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.

  • CVE-2019-20511MedMar 18, 2020
    risk 0.40cvss 6.1epss 0.01

    ERPNext 11.1.47 allows blog?blog_category= Frame Injection.

  • CVE-2026-72910HigAug 10, 2026
    risk 0.39cvss 7.1epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions across erpnext/accounts/doctype/account/account.py,…

  • CVE-2026-72909HigAug 10, 2026
    risk 0.39cvss epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not apply Customer and Supplier user permissions to…

  • CVE-2026-32954HigMar 20, 2026
    risk 0.39cvss 7.1epss 0.00

    ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-based and boolean-based blind SQL injection due to insufficient parameter validation, allowing attackers to infer database…

  • CVE-2026-53568MedJun 12, 2026
    risk 0.38cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerablity in Frappe Report/List View. This issue has been patched in versions 15.107.2 and 16.17.4.

  • CVE-2026-50026MedJun 12, 2026
    risk 0.38cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in these endpoints allowed unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.17.0.

  • CVE-2026-44208MedJun 12, 2026
    risk 0.38cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint allows for unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.17.0.

  • CVE-2026-44207MedJun 12, 2026
    risk 0.38cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access other users' email configuration details. This issue has been patched in versions 15.107.0 and 16.17.0.

  • CVE-2026-44206MedJun 12, 2026
    risk 0.38cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possible through exploiting an endpoint. This issue has been patched in versions 15.107.2 and 16.17.4.

  • CVE-2026-47739MedJun 12, 2026
    risk 0.38cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possible due to lack of sanitization. This issue has been patched in versions 15.106.0 and 16.16.0.

  • CVE-2026-44205MedJun 12, 2026
    risk 0.38cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user profile image section allows an attacker to execute malicious scripts in the browsers of other users. This issue has been patched in version 15.106.0.

  • CVE-2026-41581MedJun 12, 2026
    risk 0.38cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Injection via get_blog_list. This issue has been patched in versions 15.106.0 and 16.16.0.

  • CVE-2025-53545MedJul 8, 2025
    risk 0.38cvss epss 0.00

    Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Users can circumvent 2FA login for users due to a lack of server side validation for the same. This vulnerability is fixed in commit…

  • CVE-2026-72908MedAug 10, 2026
    risk 0.35cvss 6.5epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WHERE clause from request-influenced posting_date and args values, allowing an…

  • CVE-2026-72907MedAug 10, 2026
    risk 0.35cvss 6.5epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without enforcing Account create permission, allowing an authenticated limited user to…

  • CVE-2026-44445MedMay 13, 2026
    risk 0.35cvss 6.5epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enables an authenticated attacker to read files from the local file system,…

  • CVE-2026-44440MedMay 13, 2026
    risk 0.35cvss 6.5epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on an endpoint allows an authenticated adjacent attacker to read arbitrary files.…

  • CVE-2026-3673MedApr 22, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where tags are rendered. The vulnerable renderer interpolates tag content into HTML attributes and element content without escaping.…

  • CVE-2026-41320MedApr 21, 2026
    risk 0.35cvss 6.5epss 0.00

    Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to.…

  • CVE-2026-40889MedApr 21, 2026
    risk 0.35cvss 6.5epss 0.00

    Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthorized files by exploiting certain api endpoint. Versions 15.58.2 and 16.4.2 contain a patch. No known workarounds are available.

  • CVE-2026-40888MedApr 21, 2026
    risk 0.35cvss 6.5epss 0.00

    Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized information by exploiting certain api endpoint. Versions 15.58.1 and 16.4.1 contain a patch. No known…

  • CVE-2026-31879MedMar 11, 2026
    risk 0.35cvss 5.4epss 0.00

    Frappe is a full-stack web application framework. Prior to 14.100.2, 15.101.0, and 16.10.0, due to a lack of validation and improper permission checks, users could modify other user's private workspaces. Specially crafted requests could lead to stored XSS here. This…

  • CVE-2025-65923MedFeb 3, 2026
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1 when using the Update Existing Recordsoption. An attacker can embed malicious JavaScript code into a CSV field, which is then stored in the database and…

  • CVE-2025-66581MedDec 5, 2025
    risk 0.35cvss 6.5epss 0.00

    Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, a flaw in the server-side authorization logic allowed authenticated users to perform actions beyond their assigned roles across multiple features. Because the…

  • CVE-2025-64707MedNov 12, 2025
    risk 0.35cvss 5.4epss 0.00

    Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, when admins revoked a role from the user, the effect was not immediate because of caching. The issue has been fixed in version 2.41.0 by ensuring…

  • CVE-2025-56379MedOct 2, 2025
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.

  • CVE-2024-24812MedFeb 7, 2024
    risk 0.35cvss 5.4epss 0.00

    Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and a tightly integrated client side library. Prior to versions 14.59.0 and 15.5.0, portal pages are susceptible to Cross-Site Scripting (XSS) which can be used to inject malicious…

  • CVE-2026-26031MedFeb 11, 2026
    risk 0.34cvss 5.3epss 0.00

    Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified in Frappe Learning, where unauthorised users were able to access the full list of enrolled students (by email) in batches. This…

  • CVE-2026-49391MedAug 6, 2026
    risk 0.33cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering previews and results, allowing an authenticated importer to persist script content that executes when another user views the…

  • CVE-2026-47185MedAug 6, 2026
    risk 0.33cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing workspace ownership, allowing modification of another user's private workspace and persistent script…

  • CVE-2026-50701MedJun 24, 2026
    risk 0.33cvss epss 0.00

    A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component.

  • CVE-2026-42840MedJun 3, 2026
    risk 0.33cvss epss 0.00

    An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of Sale (POS) interface for every operator who selects that customer. This issue affects ERPNext: 16.16.0.

  • CVE-2026-44441MedMay 13, 2026
    risk 0.33cvss 5.0epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in…

  • CVE-2026-41430MedApr 24, 2026
    risk 0.33cvss 6.1epss 0.00

    Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect parameter on login page is vulnerable to reflected XSS. The patch in commit 16d1b6ca2559f858a1de77bcb03fd7f1b81671c6 fixes the issue…

  • CVE-2026-34606MedApr 2, 2026
    risk 0.33cvss 6.1epss 0.00

    Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, Frappe LMS was vulnerable to stored XSS. This issue has been patched in version 2.48.0.

  • CVE-2026-31878MedMar 11, 2026
    risk 0.33cvss 5.0epss 0.00

    Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a crafted request to an endpoint which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in 14.100.1,…