frappe
Enterprise Softwareoss-project
Latest CVEs
The 15 most recently published vulnerabilities affecting frappe.
- CVE-2026-96672Frappe ERPNext before 16.34.1 Unauthorized Method Invocation6.4
- CVE-2026-94113Frappe ERPNext before 15.121.0 and 16.34.0 Missing Authorization in Timesheet Endpoints6.5
- CVE-2026-54343Frappe LMS: Path Traversal in SCORM File Serving
- CVE-2026-54524Frappe HR: SQL Injection in HRMS Salary Payments Based on Payment Mode Report
- CVE-2023-51769Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.6.1
- CVE-2026-53761Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api
- CVE-2026-82634Frappe Framework Development Branch Incorrect Authorization via Jinja Template Preview Endpoint6.5
- CVE-2026-81731Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description5.4
- CVE-2026-66003Frappe: Access control bypass via REST API dot-notation fields on linked doctypes
- CVE-2026-66002Frappe: User Enumeration via PDDR
- CVE-2026-66001Frappe: Improper Authorization in OAuth2 Consent Endpoint
- CVE-2026-62315Frappe: Mass assignment via set_value
- CVE-2026-63654Frappe: Unauthenticated Workflow approval via confirm_action
- CVE-2026-53569Frappe: Missing authorization in toggle_like and mark_as_seen
- CVE-2026-65822ERPNext: SQL Injection in "Inactive Customers" report via unvalidated `doctype` filter7.6