frappe
Enterprise Softwareoss-project
Latest CVEs
The 15 most recently published vulnerabilities affecting frappe.
- CVE-2025-58375Frappe has potential SQL Injection due to missing validation8.1
- CVE-2026-55242ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefix8.8
- CVE-2026-46546Frappe LMS: HTML injection in user-controlled metadata5.4
- CVE-2026-45081Frappe HR: Permission Bypass in HRMS Leave Details API6.5
- CVE-2026-44448ERPNext: Unauthorised Document modification due to missing validation5.9
- CVE-2026-44447ERPNext: Possibility of SQL Injection due to missing validation8.8
- CVE-2026-44446ERPNext: Possibility of SQL Injection due to missing validation8.8
- CVE-2026-44445ERPNext: XML External Entity (XEE) Reference Vulnerability in the EDI Module6.5
- CVE-2026-44441ERPNext: Possible SSRF by any authenticated user5.0
- CVE-2026-44440ERPNext: Path Traversal Leading to Sensitive File Exposure6.5
- CVE-2026-44442ERPNext: Unauthorised Document modification due to missing validation9.9
- CVE-2023-54345Frappe Framework ERPNext 13.4.0 Remote Code Execution8.8
- CVE-2026-38431ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed ...9.8
- CVE-2026-38432ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript ...6.1
- CVE-2026-41430Press vulnerable to reflected XSS on login redirection6.1