VYPR

Vendor CVEs

Frappe

All CVEs

195 total · sorted by risk
  • CVE-2025-11281MedOct 5, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished Course Handler. Such manipulation leads to improper access controls. The attack may be launched remotely. This attack is…

  • CVE-2026-50712MedJun 24, 2026
    risk 0.31cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component

  • CVE-2026-50709MedJun 24, 2026
    risk 0.31cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.

  • CVE-2026-50708MedJun 24, 2026
    risk 0.31cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component.

  • CVE-2026-50703MedJun 24, 2026
    risk 0.31cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer.

  • CVE-2026-42839MedJun 3, 2026
    risk 0.31cvss epss 0.00

    An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, description, or image fields of an Item and trigger unescaped rendering in the Point of Sale (POS) cart interface for every operator who adds that item to a…

  • CVE-2026-44448MedMay 13, 2026
    risk 0.31cvss 5.9epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 15.102.0 and 16.11.0.

  • CVE-2026-50711MedJun 24, 2026
    risk 0.30cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component.

  • CVE-2026-50710MedJun 24, 2026
    risk 0.30cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.

  • CVE-2026-50705MedJun 24, 2026
    risk 0.30cvss epss 0.00

    A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer.

  • CVE-2026-50704MedJun 24, 2026
    risk 0.30cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer.

  • CVE-2026-50700MedJun 24, 2026
    risk 0.30cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function.

  • CVE-2026-50699MedJun 24, 2026
    risk 0.30cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users…

  • CVE-2026-50698MedJun 24, 2026
    risk 0.30cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HTML output in the Audit Trail component.

  • CVE-2026-3837MedApr 22, 2026
    risk 0.28cvss 5.4epss 0.00

    An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the affected document in Desk. The vulnerable formatter implementations interpolate stored values into raw HTML attributes and element…

  • CVE-2026-23497MedJan 14, 2026
    risk 0.28cvss 5.4epss 0.00

    Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and earlier, there is a stored XSS vulnerability where a specially crafted image filename could execute malicious JavaScript when rendered on course or jobs pages.

  • CVE-2025-66436MedDec 15, 2025
    risk 0.28cvss 4.3epss 0.00

    An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (terms) using frappe.render_template() with a user-supplied context (doc). Although…

  • CVE-2025-66435MedDec 15, 2025
    risk 0.28cvss 4.3epss 0.00

    An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (contract_terms) using frappe.render_template() with a user-supplied context (doc).…

  • CVE-2025-67734MedDec 12, 2025
    risk 0.28cvss 5.4epss 0.00

    Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allowed authenticated attackers to enter JavaScript through the Company Website field of the Job Form, exposing users to an XSS attack. The script…

  • CVE-2025-67730MedDec 12, 2025
    risk 0.28cvss 5.4epss 0.00

    Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allow authenticated users to add malicious HTML and JavaScript through description fields in the Job, Course and Batch forms. This issue is fixed in…

  • CVE-2025-64705MedNov 12, 2025
    risk 0.28cvss 4.3epss 0.00

    Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, users were able to access the submissions made by other students The issue has been fixed in version 2.41.0 by ensuring proper roles and…

  • CVE-2025-55006MedAug 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not adequately sanitize uploaded SVG files. This allowed users to upload SVG files containing embedded JavaScript or other potentially…

  • CVE-2026-66058MedAug 7, 2026
    risk 0.27cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixed in versions 16.20.0 and 15.112.0.

  • CVE-2026-66059MedAug 7, 2026
    risk 0.27cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0.

  • CVE-2026-47182MedJun 12, 2026
    risk 0.27cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private files by guessing the file path. This issue has been patched in version 16.17.4.

  • CVE-2026-44976MedJun 12, 2026
    risk 0.27cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue has been patched in version 16.17.4.

  • CVE-2026-44975MedJun 12, 2026
    risk 0.27cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users in the system. This issue has been patched in versions 15.107.2 and 16.17.4.

  • CVE-2026-26977MedFeb 20, 2026
    risk 0.27cvss 5.3epss 0.00

    Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized users are able to access the details of unpublished courses via API endpoints. A fix for this issue is planned for the 2.45.0 release.

  • CVE-2025-65924MedFeb 3, 2026
    risk 0.27cvss 4.1epss 0.00

    ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `` hyperlinks in fields that are intended for plain text. Although JavaScript is blocked (preventing XSS), the HTML is still preserved in the generated PDF document. As a result, an attacker can…

  • CVE-2023-41328MedSep 6, 2023
    risk 0.27cvss 4.2epss 0.00

    Frappe is a low code web framework written in Python and Javascript. A SQL Injection vulnerability has been identified in the Frappe Framework which could allow a malicious actor to access sensitive information. This issue has been addressed in versions 13.46.1 and 14.20.0.…

  • CVE-2025-11280LowOct 5, 2025
    risk 0.24cvss 3.7epss 0.00

    A flaw has been found in Frappe LMS 2.35.0. Impacted is an unknown function of the file /files/ of the component Assignment Picture Handler. This manipulation causes direct request. The attack may be initiated remotely. The attack's complexity is rated as high. The…

  • CVE-2026-72906MedAug 10, 2026
    risk 0.21cvss 4.3epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py lacks a Process Statement Of Accounts permission check,…

  • CVE-2026-39415MedApr 8, 2026
    risk 0.21cvss 4.3epss 0.00

    Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0, a vulnerability has been identified in Frappe Learning where quiz scores can be modified by students before submission. The application currently relies on…

  • CVE-2025-11283LowOct 5, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. Executing manipulation of the argument Description can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly…

  • CVE-2025-11282LowOct 5, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in Frappe LMS 2.34.x/2.35.0. The impacted element is an unknown function of the component Incomplete Fix CVE-2025-55006. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made…

  • CVE-2025-59421LowSep 18, 2025
    risk 0.11cvss epss 0.00

    Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). A bad actor can flood the inbox of a user by repeatedly sending invites (duplicate). The issue is fixed in commit…

  • CVE-2026-66000LowAug 7, 2026
    risk 0.08cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by…

  • CVE-2026-46546LowJun 10, 2026
    risk 0.07cvss epss 0.00

    Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors'…

  • CVE-2023-46127MedOct 23, 2023
    risk 0.03cvss 5.4epss 0.37

    Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vulnerability has been…

  • CVE-2005-3819Nov 26, 2005
    risk 0.03cvss epss 0.03

    Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authentication via the (1) user_name and (2) date parameter in the HelpDesk module.

  • CVE-2024-49751LowOct 23, 2024
    risk 0.01cvss epss 0.01

    Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Prior to commit 5d118a902872d7941f099ad1fb918e2421e79ccd, a user could inject HTML through SaaS signup inputs. The user who injected the unsafe…

  • CVE-2026-12895HigJul 29, 2026
    risk 0.00cvss epss 0.00

    SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing parameterized queries, allowing the name (docname) of a Supplier record containing…

  • CVE-2026-39385HigJul 20, 2026
    risk 0.00cvss epss 0.00

    Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.

  • CVE-2026-55242HigJul 15, 2026
    risk 0.00cvss 8.8epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data…

  • CVE-2026-58503MedJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.

  • CVE-2026-55852HigJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tarfile members were not sufficiently checked before extraction. This issue is fixed in versions 16.23.0 and 15.112.0.

  • CVE-2026-49394HigJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed in version 16.19.0.

  • CVE-2026-48127MedJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints such as add_attachments. This issue is fixed in versions 16.20.0 and 15.110.0.

  • CVE-2026-47422MedJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2.

  • CVE-2026-47199LowJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT INTO OUTFILE queries, which could potentially work on self-hosted sites if database permissions are not well aligned and MySQL FILE privileges are available.…