Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

frappe — Vulnerabilities & Security Advisories 70

All 70 CVE vulnerabilities found in frappe, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for the frappe framework, covering common weakness types and associated security tags. It collects data regarding critical flaws, code injection risks, and authentication bypasses that have been identified within the ecosystem over the past five years. By centralizing this information, the page allows users to track vendor advisories from the official maintainers, understand the prevalence and impact of specific weakness classes across different modules, and look up the complete vulnerability history of the product to assess long-term security posture. The content includes details on affected versions, severity ratings, and available patches, providing a comprehensive view of the threat landscape for frappe applications. This resource is designed for security analysts, developers, and system administrators who need to make informed decisions about patching and mitigation strategies. It does not offer real-time monitoring or automated threat detection services, but rather serves as a static reference for historical and current known issues. Users are encouraged to cross-reference this data with official vendor bulletins and independent security research for the most up-to-date guidance on remediation.

Vendor: frappe

CVE ID Title CVSS Severity Published
CVE-2026-66002 Frappe: User Enumeration via PDDR CWE-204 6.9 Medium 2026-08-20
CVE-2026-66001 Frappe: Improper Authorization in OAuth2 Consent Endpoint CWE-352 8.5 High 2026-08-20
CVE-2026-62315 Frappe: Mass assignment via set_value CWE-915 7.1 High 2026-08-20
CVE-2026-63654 Frappe: Unauthenticated Workflow approval via confirm_action CWE-352 6.9 Medium 2026-08-20
CVE-2026-53569 Frappe: Missing authorization in toggle_like and mark_as_seen CWE-862 5.3 Medium 2026-08-20
CVE-2026-66000 Frappe: Unrestricted access to Document Follow APIs CWE-863 2.3 Low 2026-08-07
CVE-2025-58375 Frappe has potential SQL Injection due to missing validation CWE-89 8.1 High 2026-08-07
CVE-2026-66058 Frappe: Unrestricted access to a Document Follow API CWE-862 5.3 Medium 2026-08-07
CVE-2026-66059 Frappe: Field-level permission bypass via Document Follow CWE-863 5.3 Medium 2026-08-07
CVE-2026-49391 Frappe: Stored XSS in Column Headers via Data Import CWE-79 5.1 Medium 2026-08-06
CVE-2026-47765 Frappe: Lack of Permissions in restore/bulk_restore CWE-862 7.1 High 2026-08-06
CVE-2026-47194 Frappe: Host header poisoning can redirect magic login links to an attacker-controlled domain CWE-346 8.6 High 2026-08-06
CVE-2026-47185 Frappe Has Broken Access Control in its Workspace Save API CWE-863 5.1 Medium 2026-08-06
CVE-2026-55852 Frappe: TarSlip RCE in Package Import CWE-22 - - 2026-07-10
CVE-2026-42219 Frappe: Path Traversal via /backups Route CWE-22 - - 2026-07-10
CVE-2026-49394 Frappe: Auth. bypass via update_page CWE-862 - - 2026-07-10
CVE-2026-48127 Frappe: Arbitrary Attachment Injection via add_attachments and upload_file CWE-862 - - 2026-07-10
CVE-2026-41482 Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Generator CWE-22 - - 2026-07-10
CVE-2026-47199 Frappe: check_safe_sql_query Permits SELECT INTO OUTFILE CWE-89 - - 2026-07-10
CVE-2026-58503 Frappe: Unauthenticated User Enumeration via reset_password CWE-203 - - 2026-07-10
CVE-2026-47422 Frappe: Unrestricted API access to save_report CWE-862 - - 2026-07-10
CVE-2026-53568 Frappe: Stored XSS in Frappe Report/List View via 'set_link_title_field_value' CWE-79 - - 2026-06-12
CVE-2026-50026 Frappe: Lack of permissions checks in 'relink' and 'set_email_password' endpoints CWE-862 - - 2026-06-12
CVE-2026-47182 Frappe: Broken Access Control on Private Files CWE-284 - - 2026-06-12
CVE-2026-44976 Frappe: IDOR in update_onboarding_step CWE-284 - - 2026-06-12
CVE-2026-44975 Frappe: Missing authorization on reset form tours CWE-862 - - 2026-06-12
CVE-2026-44206 Frappe: DB Schema Enumeration via Frappe-Authorization-Source CWE-200 - - 2026-06-12
CVE-2026-44207 Frappe: Insecure Direct Object Reference for email accounts CWE-639 - - 2026-06-12
CVE-2026-44208 Frappe: IDOR in `submit_discussion()` CWE-284 - - 2026-06-12
CVE-2026-44205 Frappe: Stored Cross-Site Scripting (XSS) in User Profile through Image Upload CWE-79 - - 2026-06-12

All 70 known CVE vulnerabilities affecting frappe with full Chinese analysis, references, and POCs where available.