frappe
Enterprise Softwareoss-project
Latest CVEs
The 15 most recently published vulnerabilities affecting frappe.
- CVE-2026-72911ERPNext: Possibility of server-side template injection due to missing validation9.9
- CVE-2026-72910ERPNext: Unauthorised modification of master data due to missing validation7.1
- CVE-2026-72908ERPNext: Possibility of SQL injection due to missing validation6.5
- CVE-2026-72907ERPNext: Broken Access Control on certain endpoint6.5
- CVE-2026-72906ERPNext: Unauthorised triggering of automated emails due to missing validation4.3
- CVE-2025-58375Frappe has potential SQL Injection due to missing validation8.1
- CVE-2026-55242ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefix8.8
- CVE-2026-46546Frappe LMS: HTML injection in user-controlled metadata5.4
- CVE-2026-45081Frappe HR: Permission Bypass in HRMS Leave Details API6.5
- CVE-2026-44448ERPNext: Unauthorised Document modification due to missing validation5.9
- CVE-2026-44447ERPNext: Possibility of SQL Injection due to missing validation8.8
- CVE-2026-44446ERPNext: Possibility of SQL Injection due to missing validation8.8
- CVE-2026-44445ERPNext: XML External Entity (XEE) Reference Vulnerability in the EDI Module6.5
- CVE-2026-44441ERPNext: Possible SSRF by any authenticated user5.0
- CVE-2026-44440ERPNext: Path Traversal Leading to Sensitive File Exposure6.5