VYPR

Vendor CVEs

Frappe

All CVEs

195 total · sorted by risk
  • CVE-2026-42219MedJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was possible due to lack of hardening. This issue is fixed in versions 16.19.0 and 15.109.0.

  • CVE-2026-41482HigJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion were possible through secure local resource access in the Chrome PDF Generator. This issue is fixed in version 16.18.3.

  • CVE-2026-27471CriFeb 21, 2026
    risk 0.00cvss 9.1epss 0.00

    ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.

  • CVE-2026-25956MedFeb 10, 2026
    risk 0.00cvss 6.1epss 0.00

    Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious signup URL for a frappe site which could lead to an open redirect (or reflected XSS, depending on the crafted payload) when a user signs up. This vulnerability is…

  • CVE-2025-68953HigJan 5, 2026
    risk 0.00cvss 7.5epss 0.00

    Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests that are vulnerable to path traversal attacks. Arbitrary files from the server could be retrieved due to a lack of proper sanitization on some requests. This…

  • CVE-2025-68928MedDec 29, 2025
    risk 0.00cvss 5.4epss 0.00

    Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could set crafted URLs in a website field, which were not sanitized, causing cross-site scripting. Version 1.56.2 fixes the issue. No known workarounds are available.

  • CVE-2025-66205HigDec 1, 2025
    risk 0.00cvss 7.1epss 0.00

    Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to lack of validation of parameters. Some information like version could be retrieved. This vulnerability is fixed in 15.86.0 and…

  • CVE-2025-11461HigNov 26, 2025
    risk 0.00cvss 8.8epss 0.00

    Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. This issue affects Frappe CRM: 1.53.1.

  • CVE-2025-62779MedOct 27, 2025
    risk 0.00cvss 5.4epss 0.00

    Frappe Learning is a learning system that helps users structure their content. In Frappe Learning 2.39.1 and earlier, users were able to add HTML through input fields in the Job Form.

  • CVE-2025-62778MedOct 27, 2025
    risk 0.00cvss 5.3epss 0.00

    Frappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to access the Quiz Form if they had the URL.

  • CVE-2025-62158MedOct 10, 2025
    risk 0.00cvss 5.3epss 0.00

    Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially exposed student-uploaded files to the public.…

  • CVE-2025-52042HigOct 1, 2025
    risk 0.00cvss 8.2epss 0.00

    In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/request_for_quotation/request_for_quotation.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query via the txt…

  • CVE-2025-52041HigOct 1, 2025
    risk 0.00cvss 8.2epss 0.00

    In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reconciliation.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the…

  • CVE-2025-52040HigOct 1, 2025
    risk 0.00cvss 8.2epss 0.00

    In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker can extract all information from databases by injecting a SQL query into the blanket_order_type parameter.

  • CVE-2025-52039HigOct 1, 2025
    risk 0.00cvss 8.2epss 0.00

    In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_request/material_request.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the…

  • CVE-2025-52050MedSep 30, 2025
    risk 0.00cvss 6.5epss 0.00

    In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_program/loyalty_program.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the…

  • CVE-2025-52049MedSep 30, 2025
    risk 0.00cvss 6.5epss 0.00

    In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query into the timelog parameter.

  • CVE-2025-52047MedSep 30, 2025
    risk 0.00cvss 6.5epss 0.00

    In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the filters.disabled parameter.

  • CVE-2025-52043MedSep 30, 2025
    risk 0.00cvss 6.5epss 0.00

    In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_accounts_importer.py is vulnerable to SQL injection, which allows an attacker to extract all information from databases by injecting a SQL query into the company…

  • CVE-2025-59415MedSep 17, 2025
    risk 0.00cvss 4.6epss 0.00

    Frappe Learning is a learning system that helps users structure their content. In versions 2.34.1 and below, there is a security vulnerability in Frappe Learning where the system did not adequately sanitize the content uploaded in the profile bio. Malicious SVG files could be…

  • CVE-2025-52044HigSep 16, 2025
    risk 0.00cvss 7.5epss 0.00

    In Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query into inventory_dimensions_dict parameter.

  • CVE-2025-58439HigSep 6, 2025
    risk 0.00cvss 8.1epss 0.00

    ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left certain endpoints vulnerable to error-based SQL Injection. Some information like version could be retrieved. This issue is…

  • CVE-2025-55732HigAug 20, 2025
    risk 0.00cvss 7.5epss 0.00

    Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass of the official patch released…

  • CVE-2025-55731HigAug 20, 2025
    risk 0.00cvss 8.8epss 0.00

    Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15.

  • CVE-2025-52898HigJun 30, 2025
    risk 0.00cvss 8.8epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting access to a user's password reset token. This can only be exploited on self hosted instances configured in a certain way.…

  • CVE-2025-52896MedJun 30, 2025
    risk 0.00cvss 5.4epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading to cross-site scripting (XSS). This issue has been patched in versions 14.94.2 and 15.57.0. There…

  • CVE-2025-52895HigJun 30, 2025
    risk 0.00cvss 7.5epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted request, which could allow malicious person to gain access to sensitive information. This issue has been patched in versions 14.94.3…

  • CVE-2024-50356NonOct 31, 2024
    risk 0.00cvss 0.0epss 0.00

    Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). The password could be reset by anyone who have access to the mail inbox circumventing the 2FA. Even though they wouldn't be able to login by…

  • CVE-2024-34074MedMay 14, 2024
    risk 0.00cvss 6.1epss 0.01

    Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerability is fixed in 15.26.0 and…

  • CVE-2023-5555MedOct 12, 2023
    risk 0.00cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Generic in GitHub repository frappe/lms prior to 5614a6203fb7d438be8e2b1e3030e4528d170ec4.

  • CVE-2022-3988LowNov 14, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functionality of the file frappe/templates/includes/navbar/navbar_search.html of the component Search. The manipulation of the argument q leads to cross site scripting.…

  • CVE-2022-23055Jun 22, 2022
    risk 0.00cvss epss 0.01

    In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker…

  • CVE-2022-23058Jun 22, 2022
    risk 0.00cvss epss 0.01

    ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.

  • CVE-2022-23057MedJun 22, 2022
    risk 0.00cvss 5.4epss 0.01

    In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.

  • CVE-2022-23056Jun 22, 2022
    risk 0.00cvss epss 0.01

    In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.

  • CVE-2020-35175MedDec 11, 2020
    risk 0.00cvss 5.3epss 0.01

    Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

  • CVE-2020-27508HigDec 11, 2020
    risk 0.00cvss 7.5epss 0.01

    In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security.

  • CVE-2019-20529HigMar 18, 2020
    risk 0.00cvss 7.5epss 0.01

    In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files.

  • CVE-2019-15700MedAug 27, 2019
    risk 0.00cvss 6.1epss 0.01

    public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.

  • CVE-2019-14967MedAug 12, 2019
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.

  • CVE-2019-14966HigAug 12, 2019
    risk 0.00cvss 8.8epss 0.02

    An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.

  • CVE-2019-14965CriAug 12, 2019
    risk 0.00cvss 9.8epss 0.03

    An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.

  • CVE-2006-4617Sep 7, 2006
    risk 0.00cvss epss 0.01

    Unrestricted file upload vulnerability in fileupload.html in vtiger CRM 4.2.4, and possibly earlier versions, allows remote attackers to upload and execute arbitrary files with executable extensions in the /cashe/mails folder.

  • CVE-2005-3821Nov 26, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in vTiger CRM 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via multiple vectors, including the account name.

  • CVE-2005-3822Nov 26, 2005
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username in the login form or (2) record parameter, as demonstrated in the EditView action for the Contacts module.

Page 4 of 4