vciy

CVEs we hold for Frappe

Records whose assigning authority named Frappe as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-82634Frappe Framework Development Branch Incorrect Authorization via Jinja Template Preview Endpointfrappe
CVE-2026-81731Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Descriptionfrappe
CVE-2026-72911ERPNext: Possibility of server-side template injection due to missing validationfrappe erpnext
CVE-2026-72910ERPNext: Unauthorised modification of master data due to missing validationfrappe erpnext
CVE-2026-72909ERPNext: Broken Access Control on certain endpointsfrappe erpnext
CVE-2026-72908ERPNext: Possibility of SQL injection due to missing validationfrappe erpnext
CVE-2026-72907ERPNext: Broken Access Control on certain endpointfrappe erpnext
CVE-2026-72906ERPNext: Unauthorised triggering of automated emails due to missing validationfrappe erpnext
CVE-2026-66059Frappe: Field-level permission bypass via Document Followfrappe
CVE-2026-66058Frappe: Unrestricted access to a Document Follow APIfrappe
CVE-2026-66003Frappe: Access control bypass via REST API dot-notation fields on linked doctypesfrappe
CVE-2026-66002Frappe: User Enumeration via PDDRfrappe
CVE-2026-66001Frappe: Improper Authorization in OAuth2 Consent Endpointfrappe
CVE-2026-66000Frappe: Unrestricted access to Document Follow APIsfrappe
CVE-2026-65974ERPNext: Server-Side Template Injection leading to Remote Code Executionfrappe erpnext
CVE-2026-65822ERPNext: SQL Injection in "Inactive Customers" report via unvalidated `doctype` filterfrappe erpnext
CVE-2026-63654Frappe: Unauthenticated Workflow approval via confirm_actionfrappe
CVE-2026-62315Frappe: Mass assignment via set_valuefrappe
CVE-2026-58503Frappe: Unauthenticated User Enumeration via reset_passwordfrappe
CVE-2026-55852Frappe: TarSlip RCE in Package Importfrappe
CVE-2026-55242ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefixfrappe erpnext
CVE-2026-54524Frappe HR: SQL Injection in HRMS Salary Payments Based on Payment Mode Reportfrappe hrms
CVE-2026-54343Frappe LMS: Path Traversal in SCORM File Servingfrappe lms
CVE-2026-53761Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/apifrappe crm
CVE-2026-53569Frappe: Missing authorization in toggle_like and mark_as_seenfrappe
CVE-2026-53568Frappe: Stored XSS in Frappe Report/List View via 'set_link_title_field_value'frappe
CVE-2026-50712Frappe Framework 17.0.0-dev - Stored XSS in Tree View node label renderingFrappe Framework
CVE-2026-50711Frappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields renderingFrappe Framework
CVE-2026-50710Frappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_configFrappe Framework
CVE-2026-50709Frappe Framework 17.0.0-dev - Stored XSS in Notifications Events color renderingFrappe Framework
CVE-2026-50708Frappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result renderingFrappe Framework
CVE-2026-50705Frappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline renderingFrappe Framework
CVE-2026-50704Frappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs renderingFrappe Framework
CVE-2026-50703Frappe Framework 17.0.0-dev - Stored XSS in Desktop Icon label renderingFrappe Framework
CVE-2026-50701Frappe Framework 17.0.0-dev - Reflected DOM XSS in dashboard-view breadcrumb renderingFrappe Framework
CVE-2026-50700Frappe Framework 17.0.0-dev - Stored XSS in frappe.get_avatar image renderingFrappe Framework
CVE-2026-50699Frappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule renderingFrappe Framework
CVE-2026-50698Frappe Framework 17.0.0-dev - Stored XSS in Audit Trail template renderingFrappe Framework
CVE-2026-50026Frappe: Lack of permissions checks in 'relink' and 'set_email_password' endpointsfrappe
CVE-2026-49394Frappe: Auth. bypass via update_pagefrappe
CVE-2026-49391Frappe: Stored XSS in Column Headers via Data Importfrappe
CVE-2026-48127Frappe: Arbitrary Attachment Injection via add_attachments and upload_filefrappe
CVE-2026-47765Frappe: Lack of Permissions in restore/bulk_restorefrappe
CVE-2026-47739Frappe: Stored XSS in Notefrappe
CVE-2026-47422Frappe: Unrestricted API access to save_reportfrappe
CVE-2026-47199Frappe: check_safe_sql_query Permits SELECT INTO OUTFILEfrappe
CVE-2026-47194Frappe: Host header poisoning can redirect magic login links to an attacker-controlled domainfrappe
CVE-2026-47185Frappe Has Broken Access Control in its Workspace Save APIfrappe
CVE-2026-47182Frappe: Broken Access Control on Private Filesfrappe
CVE-2026-46546Frappe LMS: HTML injection in user-controlled metadatafrappe lms
CVE-2026-45081Frappe HR: Permission Bypass in HRMS Leave Details APIfrappe hrms
CVE-2026-44976Frappe: IDOR in update_onboarding_stepfrappe
CVE-2026-44975Frappe: Missing authorization on reset form toursfrappe
CVE-2026-44448ERPNext: Unauthorised Document modification due to missing validationfrappe erpnext
CVE-2026-44447ERPNext: Possibility of SQL Injection due to missing validationfrappe erpnext
CVE-2026-44446ERPNext: Possibility of SQL Injection due to missing validationfrappe erpnext
CVE-2026-44445ERPNext: XML External Entity (XEE) Reference Vulnerability in the EDI Modulefrappe erpnext
CVE-2026-44442ERPNext: Unauthorised Document modification due to missing validationfrappe erpnext
CVE-2026-44441ERPNext: Possible SSRF by any authenticated userfrappe erpnext
CVE-2026-44440ERPNext: Path Traversal Leading to Sensitive File Exposurefrappe erpnext
CVE-2026-44208Frappe: IDOR in `submit_discussion()`frappe
CVE-2026-44207Frappe: Insecure Direct Object Reference for email accountsfrappe
CVE-2026-44206Frappe: DB Schema Enumeration via Frappe-Authorization-Sourcefrappe
CVE-2026-44205Frappe: Stored Cross-Site Scripting (XSS) in User Profile through Image Uploadfrappe
CVE-2026-42840ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literalsFrappe ERPNext
CVE-2026-42839ERPNext 16.16.0 - Stored XSS in POS cart item renderingFrappe ERPNext
CVE-2026-42219Frappe: Path Traversal via /backups Routefrappe
CVE-2026-41581Frappe Vulnerable to Possible SQL Injection via get_blog_listfrappe
CVE-2026-41482Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Generatorfrappe
CVE-2026-41430Press vulnerable to reflected XSS on login redirectionfrappe press
CVE-2026-41320Frappe HR has possibility of SQL Injection due to improper field sanitizationfrappe hrms
CVE-2026-41317Frappe Press has an unsafe HTTP method / CSRF-adjacent issue on API secret generationfrappe press
CVE-2026-40889Frappe HR has Improper Access Control on Filesfrappe hrms
CVE-2026-40888Frappe HR vulnerable to Improper Access Controlfrappe hrms
CVE-2026-39415Frappe Learning Management System has Client-Side Manipulation of Quiz Scoresfrappe lms
CVE-2026-39405Frappe has Path Transversal via SCORMfrappe lms
CVE-2026-39385Frappe LMS enrollment bypass in paid courses via unrelated batchfrappe lms
CVE-2026-39352Frappe has an Arbitrary File Read via Path Traversal in render_includefrappe
CVE-2026-39351Frappe allows unrestricted Doctype access via API exploitfrappe
CVE-2026-3837Frappe Framework 16.10.0 - Stored DOM XSS in Multiple Field FormattersFrappe
CVE-2026-3673Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill RendererFrappe
CVE-2026-35614Frappe has a SQL injection in bulk_updatefrappe
CVE-2026-34606Stored XSS in Frappe LMSfrappe lms
CVE-2026-32954ERP has a possibility SQL Injection vulnerability due to missing validationfrappe erpnext
CVE-2026-31879Frappe Workspace modification and stored XSS due to improper resource ownership checksfrappe
CVE-2026-31878Frappe: Possible SSRF by any authenticated userfrappe
CVE-2026-31877Frappe SQL Injection due to improper field sanitizationfrappe
CVE-2026-29081Frappe: Possibility of SQL Injection due to improper fieldname sanitizationfrappe
CVE-2026-29077Frappe: Broken Access Control in DocSharefrappe
CVE-2026-28436Frappe: Stored XSS in avatar_macro.htmlfrappe
CVE-2026-27471ERP: Document access through endpoints due to missing validationfrappe erpnext
CVE-2026-26977Frappe Learning Management System exposes details of unpublished courses to unauthorized usersfrappe lms
CVE-2026-26031Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled studentsfrappe lms
CVE-2026-25956Frappe Affected by XSS and Open Redirect in Sign Upfrappe
CVE-2026-23497Frappe LMS has a Stored XSS via Unsanitized Image Filename in Course and Jobs Pagesfrappe lms
CVE-2026-13227ERPNext v16.25.0 - Improper authorization in Prospect opportunities APIFrappe ERPNext
CVE-2026-12895SQL Injection in Frappe's ERPNextFrappe ERPNext
CVE-2025-68953Certain Frappe requests are vulnerable to Path Traversalfrappe
CVE-2025-68929Frappe may be vulnerable remote code execution due to server-side template injectionfrappe
CVE-2025-68928Frappe CRM vulnerable to authenticated XSS via website fieldfrappe crm
CVE-2025-67734Frappe Authenticated Users can Execute JavaScript through its Job Formfrappe lms
CVE-2025-67730Frappe authenticated users can execute XSS through form description fieldsfrappe lms
CVE-2025-66581Frappe LMS is Missing Server-Side Authorization in Business Logicfrappe lms
CVE-2025-66206Frappe vulnerable to a path traversal allowing reading certain filesfrappe
CVE-2025-66205Frappe has the possibility of SQL Injection due to improper validationsfrappe
CVE-2025-64707Frappe LMS revoking access did not show immediate effect as roles were cachedfrappe lms
CVE-2025-64705Frappe user was able to access the submission of other studentsfrappe lms
CVE-2025-62779Frappe Learning users were able to add HTML through input fields in the Job Formfrappe lms
CVE-2025-62778Frappe Learning allowed students to access the Quiz Form via direct URLfrappe lms
CVE-2025-62407Frappe has an Open Redirect on Login Pagefrappe
CVE-2025-62158Frappe had attachments made by students to their assignments of type Text set to publicfrappe lms
CVE-2025-59421Press vulnerable to email flooding to users due to lack of validation and rate limitsfrappe press
CVE-2025-59415Frappe Learning vulnerable to Malicious Content upload via Profile bio fieldfrappe lms
CVE-2025-58439ERP: Possibility of SQL injection due to missing validationfrappe erpnext
CVE-2025-58375Frappe has potential SQL Injection due to missing validationfrappe
CVE-2025-55732Frappe has the possibility of SQL Injection due to improper validationsfrappe
CVE-2025-55731Frappe has the possibility of Authenticated SQL Injection due to improper validationsfrappe
CVE-2025-55006Frappe Learning Holds Potential for Malicious SVG Upload in Image Upload Featurefrappe lms
CVE-2025-53545Press has a potential 2FA bypassfrappe press
CVE-2025-52898Frappe account takeover via password reset token leakagefrappe
CVE-2025-52896Frappe authenticated XSS via data importfrappe
CVE-2025-52895Frappe possibility of SQL injection due to improper validationsfrappe
CVE-2025-30217Frappe has possibility of SQL injection due to improper validationsfrappe
CVE-2025-30214Frappe vulnerable to information disclosure leading to account takeoverfrappe
CVE-2025-30213Frappe has Possibility of Remote Code Execution due to improper validationfrappe
CVE-2025-30212Frappe has possibility of SQL injection due to improper validationsfrappe
CVE-2025-11461Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard ControllerFrappe CRM
CVE-2025-11283Frappe LMS Course cross site scriptingFrappe LMS
CVE-2025-11282Frappe LMS Incomplete Fix CVE-2025-55006 cross site scriptingFrappe LMS
CVE-2025-11281Frappe LMS Unpublished Course courses access controlFrappe LMS
CVE-2025-11280Frappe LMS Assignment Picture files direct requestFrappe LMS
CVE-2025-10655Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_dataFrappe HelpDesk
CVE-2024-50356Press has a potential 2FA bypassfrappe press
CVE-2024-49751Frappe Press possible HTML injection through SaaS Signup inputsfrappe press
CVE-2024-34074Frappe vuilnerable to an open redirect on login pagefrappe
CVE-2024-27105Frappe File Permissions can by bypassed using certain endpointsfrappe
CVE-2024-24813Frappe SQL Injection from reporting logicfrappe
CVE-2024-24812Frappe Authenticated Reflected Cross site scripting (XSS) in portal pagesfrappe
CVE-2023-5555Cross-site Scripting (XSS) - Generic in frappe/lmsfrappe/lms
CVE-2023-54345Frappe Framework ERPNext 13.4.0 Remote Code ExecutionFrappe Framework (ERPNext)
CVE-2023-51769no title heldFrappe
CVE-2023-46127Frappe vulnerable to HTML injection by any Desk userfrappe
CVE-2023-42807Frappe LMS SQL Injection Issue on People Pagefrappe lms
CVE-2023-41328Possibility limited SQL injection due to insufficient validation in Frappefrappe
CVE-2022-41712no title heldn/a Frappe
CVE-2022-23058ERPNext - Stored XSS in My Settingsfrappe
CVE-2022-23057ERPNext - Stored XSS in My Profilefrappe
CVE-2022-23055ERPNext - Improper user access conrolfrappe

148 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.