Home / CVEs we hold for Frappe CVEs we hold for Frappe Records whose assigning authority named Frappe as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-82634 Frappe Framework Development Branch Incorrect Authorization via Jinja Template Preview Endpoint frappe CVE-2026-81731 Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description frappe CVE-2026-72911 ERPNext: Possibility of server-side template injection due to missing validation frappe erpnext CVE-2026-72910 ERPNext: Unauthorised modification of master data due to missing validation frappe erpnext CVE-2026-72909 ERPNext: Broken Access Control on certain endpoints frappe erpnext CVE-2026-72908 ERPNext: Possibility of SQL injection due to missing validation frappe erpnext CVE-2026-72907 ERPNext: Broken Access Control on certain endpoint frappe erpnext CVE-2026-72906 ERPNext: Unauthorised triggering of automated emails due to missing validation frappe erpnext CVE-2026-66059 Frappe: Field-level permission bypass via Document Follow frappe CVE-2026-66058 Frappe: Unrestricted access to a Document Follow API frappe CVE-2026-66003 Frappe: Access control bypass via REST API dot-notation fields on linked doctypes frappe CVE-2026-66001 Frappe: Improper Authorization in OAuth2 Consent Endpoint frappe CVE-2026-66000 Frappe: Unrestricted access to Document Follow APIs frappe CVE-2026-65974 ERPNext: Server-Side Template Injection leading to Remote Code Execution frappe erpnext CVE-2026-65822 ERPNext: SQL Injection in "Inactive Customers" report via unvalidated `doctype` filter frappe erpnext CVE-2026-63654 Frappe: Unauthenticated Workflow approval via confirm_action frappe CVE-2026-58503 Frappe: Unauthenticated User Enumeration via reset_password frappe CVE-2026-55242 ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefix frappe erpnext CVE-2026-54524 Frappe HR: SQL Injection in HRMS Salary Payments Based on Payment Mode Report frappe hrms CVE-2026-54343 Frappe LMS: Path Traversal in SCORM File Serving frappe lms CVE-2026-53761 Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api frappe crm CVE-2026-53569 Frappe: Missing authorization in toggle_like and mark_as_seen frappe CVE-2026-53568 Frappe: Stored XSS in Frappe Report/List View via 'set_link_title_field_value' frappe CVE-2026-50712 Frappe Framework 17.0.0-dev - Stored XSS in Tree View node label rendering Frappe Framework CVE-2026-50711 Frappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields rendering Frappe Framework CVE-2026-50710 Frappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_config Frappe Framework CVE-2026-50709 Frappe Framework 17.0.0-dev - Stored XSS in Notifications Events color rendering Frappe Framework CVE-2026-50708 Frappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result rendering Frappe Framework CVE-2026-50705 Frappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline rendering Frappe Framework CVE-2026-50704 Frappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs rendering Frappe Framework CVE-2026-50703 Frappe Framework 17.0.0-dev - Stored XSS in Desktop Icon label rendering Frappe Framework CVE-2026-50701 Frappe Framework 17.0.0-dev - Reflected DOM XSS in dashboard-view breadcrumb rendering Frappe Framework CVE-2026-50700 Frappe Framework 17.0.0-dev - Stored XSS in frappe.get_avatar image rendering Frappe Framework CVE-2026-50699 Frappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule rendering Frappe Framework CVE-2026-50698 Frappe Framework 17.0.0-dev - Stored XSS in Audit Trail template rendering Frappe Framework CVE-2026-50026 Frappe: Lack of permissions checks in 'relink' and 'set_email_password' endpoints frappe CVE-2026-49391 Frappe: Stored XSS in Column Headers via Data Import frappe CVE-2026-48127 Frappe: Arbitrary Attachment Injection via add_attachments and upload_file frappe CVE-2026-47765 Frappe: Lack of Permissions in restore/bulk_restore frappe CVE-2026-47199 Frappe: check_safe_sql_query Permits SELECT INTO OUTFILE frappe CVE-2026-47194 Frappe: Host header poisoning can redirect magic login links to an attacker-controlled domain frappe CVE-2026-47185 Frappe Has Broken Access Control in its Workspace Save API frappe CVE-2026-46546 Frappe LMS: HTML injection in user-controlled metadata frappe lms CVE-2026-45081 Frappe HR: Permission Bypass in HRMS Leave Details API frappe hrms CVE-2026-44448 ERPNext: Unauthorised Document modification due to missing validation frappe erpnext CVE-2026-44447 ERPNext: Possibility of SQL Injection due to missing validation frappe erpnext CVE-2026-44446 ERPNext: Possibility of SQL Injection due to missing validation frappe erpnext CVE-2026-44445 ERPNext: XML External Entity (XEE) Reference Vulnerability in the EDI Module frappe erpnext CVE-2026-44442 ERPNext: Unauthorised Document modification due to missing validation frappe erpnext CVE-2026-44441 ERPNext: Possible SSRF by any authenticated user frappe erpnext CVE-2026-44440 ERPNext: Path Traversal Leading to Sensitive File Exposure frappe erpnext CVE-2026-44207 Frappe: Insecure Direct Object Reference for email accounts frappe CVE-2026-44206 Frappe: DB Schema Enumeration via Frappe-Authorization-Source frappe CVE-2026-44205 Frappe: Stored Cross-Site Scripting (XSS) in User Profile through Image Upload frappe CVE-2026-42840 ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals Frappe ERPNext CVE-2026-42839 ERPNext 16.16.0 - Stored XSS in POS cart item rendering Frappe ERPNext CVE-2026-41581 Frappe Vulnerable to Possible SQL Injection via get_blog_list frappe CVE-2026-41482 Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Generator frappe CVE-2026-41430 Press vulnerable to reflected XSS on login redirection frappe press CVE-2026-41320 Frappe HR has possibility of SQL Injection due to improper field sanitization frappe hrms CVE-2026-41317 Frappe Press has an unsafe HTTP method / CSRF-adjacent issue on API secret generation frappe press CVE-2026-40889 Frappe HR has Improper Access Control on Files frappe hrms CVE-2026-40888 Frappe HR vulnerable to Improper Access Control frappe hrms CVE-2026-39415 Frappe Learning Management System has Client-Side Manipulation of Quiz Scores frappe lms CVE-2026-39385 Frappe LMS enrollment bypass in paid courses via unrelated batch frappe lms CVE-2026-39352 Frappe has an Arbitrary File Read via Path Traversal in render_include frappe CVE-2026-39351 Frappe allows unrestricted Doctype access via API exploit frappe CVE-2026-3837 Frappe Framework 16.10.0 - Stored DOM XSS in Multiple Field Formatters Frappe CVE-2026-3673 Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer Frappe CVE-2026-32954 ERP has a possibility SQL Injection vulnerability due to missing validation frappe erpnext CVE-2026-31879 Frappe Workspace modification and stored XSS due to improper resource ownership checks frappe CVE-2026-31877 Frappe SQL Injection due to improper field sanitization frappe CVE-2026-29081 Frappe: Possibility of SQL Injection due to improper fieldname sanitization frappe CVE-2026-27471 ERP: Document access through endpoints due to missing validation frappe erpnext CVE-2026-26977 Frappe Learning Management System exposes details of unpublished courses to unauthorized users frappe lms CVE-2026-26031 Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled students frappe lms CVE-2026-25956 Frappe Affected by XSS and Open Redirect in Sign Up frappe CVE-2026-23497 Frappe LMS has a Stored XSS via Unsanitized Image Filename in Course and Jobs Pages frappe lms CVE-2026-13227 ERPNext v16.25.0 - Improper authorization in Prospect opportunities API Frappe ERPNext CVE-2025-68953 Certain Frappe requests are vulnerable to Path Traversal frappe CVE-2025-68929 Frappe may be vulnerable remote code execution due to server-side template injection frappe CVE-2025-68928 Frappe CRM vulnerable to authenticated XSS via website field frappe crm CVE-2025-67734 Frappe Authenticated Users can Execute JavaScript through its Job Form frappe lms CVE-2025-67730 Frappe authenticated users can execute XSS through form description fields frappe lms CVE-2025-66581 Frappe LMS is Missing Server-Side Authorization in Business Logic frappe lms CVE-2025-66206 Frappe vulnerable to a path traversal allowing reading certain files frappe CVE-2025-66205 Frappe has the possibility of SQL Injection due to improper validations frappe CVE-2025-64707 Frappe LMS revoking access did not show immediate effect as roles were cached frappe lms CVE-2025-64705 Frappe user was able to access the submission of other students frappe lms CVE-2025-62779 Frappe Learning users were able to add HTML through input fields in the Job Form frappe lms CVE-2025-62778 Frappe Learning allowed students to access the Quiz Form via direct URL frappe lms CVE-2025-62158 Frappe had attachments made by students to their assignments of type Text set to public frappe lms CVE-2025-59421 Press vulnerable to email flooding to users due to lack of validation and rate limits frappe press CVE-2025-59415 Frappe Learning vulnerable to Malicious Content upload via Profile bio field frappe lms CVE-2025-58439 ERP: Possibility of SQL injection due to missing validation frappe erpnext CVE-2025-58375 Frappe has potential SQL Injection due to missing validation frappe CVE-2025-55732 Frappe has the possibility of SQL Injection due to improper validations frappe CVE-2025-55731 Frappe has the possibility of Authenticated SQL Injection due to improper validations frappe CVE-2025-55006 Frappe Learning Holds Potential for Malicious SVG Upload in Image Upload Feature frappe lms CVE-2025-52898 Frappe account takeover via password reset token leakage frappe CVE-2025-52895 Frappe possibility of SQL injection due to improper validations frappe CVE-2025-30217 Frappe has possibility of SQL injection due to improper validations frappe CVE-2025-30214 Frappe vulnerable to information disclosure leading to account takeover frappe CVE-2025-30213 Frappe has Possibility of Remote Code Execution due to improper validation frappe CVE-2025-30212 Frappe has possibility of SQL injection due to improper validations frappe CVE-2025-11461 Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard Controller Frappe CRM CVE-2025-11282 Frappe LMS Incomplete Fix CVE-2025-55006 cross site scripting Frappe LMS CVE-2025-11281 Frappe LMS Unpublished Course courses access control Frappe LMS CVE-2025-11280 Frappe LMS Assignment Picture files direct request Frappe LMS CVE-2025-10655 Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data Frappe HelpDesk CVE-2024-49751 Frappe Press possible HTML injection through SaaS Signup inputs frappe press CVE-2024-34074 Frappe vuilnerable to an open redirect on login page frappe CVE-2024-27105 Frappe File Permissions can by bypassed using certain endpoints frappe CVE-2024-24812 Frappe Authenticated Reflected Cross site scripting (XSS) in portal pages frappe CVE-2023-5555 Cross-site Scripting (XSS) - Generic in frappe/lms frappe/lms CVE-2023-54345 Frappe Framework ERPNext 13.4.0 Remote Code Execution Frappe Framework (ERPNext) CVE-2023-46127 Frappe vulnerable to HTML injection by any Desk user frappe CVE-2023-41328 Possibility limited SQL injection due to insufficient validation in Frappe frappe 148 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.