Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ERPNext — Vulnerabilities & Security Advisories 30

All 30 CVE vulnerabilities found in ERPNext, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities reported against ERPNext, an open-source enterprise resource planning system developed by Frappe. It collects documented flaws, including SQL injection, cross-site scripting, and authentication bypass issues, covering advisory history from initial releases through recent updates. Readers can use this resource to track the vendor's security advisories, understand common weakness classes in ERPNext, and review the product's vulnerability history to assess risk and guide patching strategies.

Vendor: Talos

CVE ID Title CVSS Severity Published
CVE-2026-96672 Frappe ERPNext before 16.34.1 Unauthorized Method Invocation CWE-470 6.4 Medium 2026-09-23
CVE-2026-94113 Frappe ERPNext before 15.121.0 and 16.34.0 Missing Authorization in Timesheet Endpoints CWE-862 6.5 Medium 2026-09-20
CVE-2026-65822 ERPNext: SQL Injection in "Inactive Customers" report via unvalidated `doctype` filter CWE-89 7.6 High 2026-08-17
CVE-2026-65974 ERPNext: Server-Side Template Injection leading to Remote Code Execution CWE-1336 9.9 Critical 2026-08-17
CVE-2026-72911 ERPNext: Possibility of server-side template injection due to missing validation CWE-1336 9.9 Critical 2026-08-10
CVE-2026-72910 ERPNext: Unauthorised modification of master data due to missing validation CWE-862 7.1 High 2026-08-10
CVE-2026-72909 ERPNext: Broken Access Control on certain endpoints CWE-284 7.1 High 2026-08-10
CVE-2026-72908 ERPNext: Possibility of SQL injection due to missing validation CWE-89 6.5 Medium 2026-08-10
CVE-2026-72907 ERPNext: Broken Access Control on certain endpoint CWE-285 6.5 Medium 2026-08-10
CVE-2026-72906 ERPNext: Unauthorised triggering of automated emails due to missing validation CWE-862 4.3 Medium 2026-08-10
CVE-2026-13227 ERPNext v16.25.0 - Improper authorization in Prospect opportunities API CWE-862 7.1 High 2026-08-04
CVE-2026-12895 SQL Injection in Frappe's ERPNext CWE-89 7.1 High 2026-07-29
CVE-2026-55242 ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefix CWE-863 8.8 High 2026-07-15
CVE-2026-42839 ERPNext 16.16.0 - Stored XSS in POS cart item rendering CWE-79 - - 2026-06-03
CVE-2026-42840 ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals CWE-79 - - 2026-06-03
CVE-2026-44448 ERPNext: Unauthorised Document modification due to missing validation CWE-862 5.9 Medium 2026-05-13
CVE-2026-44447 ERPNext: Possibility of SQL Injection due to missing validation CWE-89 8.8 High 2026-05-13
CVE-2026-44446 ERPNext: Possibility of SQL Injection due to missing validation CWE-89 8.8 High 2026-05-13
CVE-2026-44445 ERPNext: XML External Entity (XEE) Reference Vulnerability in the EDI Module CWE-611 - - 2026-05-13
CVE-2026-44441 ERPNext: Possible SSRF by any authenticated user CWE-918 5.0 Medium 2026-05-13
CVE-2026-44440 ERPNext: Path Traversal Leading to Sensitive File Exposure CWE-22 6.5 Medium 2026-05-13
CVE-2026-44442 ERPNext: Unauthorised Document modification due to missing validation CWE-862 9.9 Critical 2026-05-13
CVE-2026-32954 ERP has a possibility SQL Injection vulnerability due to missing validation CWE-89 7.1 High 2026-03-20
CVE-2026-27471 ERP: Document access through endpoints due to missing validation CWE-862 4.3AI Medium AI 2026-02-21
CVE-2025-58439 ERP: Possibility of SQL injection due to missing validation CWE-89 8.1 High 2025-09-06
CVE-2022-23056 ERPNext - Stored XSS leads to account takover CWE-79 5.4 - 2022-06-22
CVE-2020-6145 ERPNext SQL注入漏洞 CWE-89 8.8 - 2020-08-10
CVE-2018-3883 Frappe ERPNext SQL注入漏洞 8.8 - 2018-09-12
CVE-2018-3885 Frappe ERPNext SQL注入漏洞 8.8 - 2018-09-12
CVE-2018-3884 Frappe ERPNext SQL注入漏洞 8.8 - 2018-09-12

All 30 known CVE vulnerabilities affecting ERPNext with full Chinese analysis, references, and POCs where available.