Frappe
This hub aggregates every CVE we track for Frappe, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
89
CVEs tracked
8
Critical
20
High
0
In CISA KEV
Severity distribution
MEDIUM26HIGH20CRITICAL8LOW2
Monthly trend
0
0
0
0
0
4
0
0
3
0
2
1
4
0
5
2
1
6
5
1
11
8
16
1
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Frappe.
- CVE-2023-51769Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.6.1
- CVE-2026-82634Frappe Framework Development Branch Incorrect Authorization via Jinja Template Preview Endpoint6.5
- CVE-2026-81731Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description5.4
- CVE-2026-66003Frappe: Access control bypass via REST API dot-notation fields on linked doctypes
- CVE-2026-66002Frappe: User Enumeration via PDDR
- CVE-2026-66001Frappe: Improper Authorization in OAuth2 Consent Endpoint
- CVE-2026-62315Frappe: Mass assignment via set_value
- CVE-2026-63654Frappe: Unauthenticated Workflow approval via confirm_action
- CVE-2026-53569Frappe: Missing authorization in toggle_like and mark_as_seen
- CVE-2026-66000Frappe: Unrestricted access to Document Follow APIs
- CVE-2025-58375Frappe has potential SQL Injection due to missing validation8.1
- CVE-2026-66058Frappe: Unrestricted access to a Document Follow API
- CVE-2026-66059Frappe: Field-level permission bypass via Document Follow
- CVE-2026-49391Frappe: Stored XSS in Column Headers via Data Import
- CVE-2026-47765Frappe: Lack of Permissions in restore/bulk_restore
Product normalization is registry-driven with AI assist and human review. How it works