Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

frappe — Vulnerabilities & Security Advisories 70

All 70 CVE vulnerabilities found in frappe, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for the frappe framework, covering common weakness types and associated security tags. It collects data regarding critical flaws, code injection risks, and authentication bypasses that have been identified within the ecosystem over the past five years. By centralizing this information, the page allows users to track vendor advisories from the official maintainers, understand the prevalence and impact of specific weakness classes across different modules, and look up the complete vulnerability history of the product to assess long-term security posture. The content includes details on affected versions, severity ratings, and available patches, providing a comprehensive view of the threat landscape for frappe applications. This resource is designed for security analysts, developers, and system administrators who need to make informed decisions about patching and mitigation strategies. It does not offer real-time monitoring or automated threat detection services, but rather serves as a static reference for historical and current known issues. Users are encouraged to cross-reference this data with official vendor bulletins and independent security research for the most up-to-date guidance on remediation.

Vendor: frappe

CVE ID Title CVSS Severity Published
CVE-2026-41581 Frappe Vulnerable to Possible SQL Injection via get_blog_list CWE-89 - - 2026-06-12
CVE-2026-47739 Frappe: Stored XSS in Note CWE-79 - - 2026-06-12
CVE-2026-39352 Frappe has an Arbitrary File Read via Path Traversal in render_include CWE-22 - - 2026-05-20
CVE-2026-3837 Frappe Framework 16.10.0 - Stored DOM XSS in Multiple Field Formatters CWE-79 5.4AI Medium AI 2026-04-22
CVE-2026-3673 Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer CWE-79 5.4AI Medium AI 2026-04-22
CVE-2026-39351 Frappe allows unrestricted Doctype access via API exploit CWE-862 8.8AI High AI 2026-04-07
CVE-2026-35614 Frappe has a SQL injection in bulk_update CWE-89 8.8AI High AI 2026-04-07
CVE-2026-31879 Frappe Workspace modification and stored XSS due to improper resource ownership checks CWE-79 5.4AI Medium AI 2026-03-11
CVE-2026-31878 Frappe: Possible SSRF by any authenticated user CWE-918 5.0 Medium 2026-03-11
CVE-2026-31877 Frappe SQL Injection due to improper field sanitization CWE-89 7.5AI High AI 2026-03-11
CVE-2026-29081 Frappe: Possibility of SQL Injection due to improper fieldname sanitization CWE-89 6.5 Medium 2026-03-05
CVE-2026-29077 Frappe: Broken Access Control in DocShare CWE-284 7.1 High 2026-03-05
CVE-2026-28436 Frappe: Stored XSS in avatar_macro.html CWE-79 5.4 - 2026-03-05
CVE-2026-25956 Frappe Affected by XSS and Open Redirect in Sign Up CWE-601 6.1 Medium 2026-02-10
CVE-2025-69083 WordPress Frappé theme <= 1.8 - Local File Inclusion vulnerability CWE-98 8.1 High 2026-01-06
CVE-2025-68953 Certain Frappe requests are vulnerable to Path Traversal CWE-22 7.5 High 2026-01-05
CVE-2025-68929 Frappe may be vulnerable remote code execution due to server-side template injection CWE-1336 9.1 Critical 2025-12-29
CVE-2025-66206 Frappe vulnerable to a path traversal allowing reading certain files CWE-22 6.8 Medium 2025-12-01
CVE-2025-66205 Frappe has the possibility of SQL Injection due to improper validations CWE-89 7.1 High 2025-12-01
CVE-2025-62407 Frappe has an Open Redirect on Login Page CWE-601 6.1 Medium 2025-10-16
CVE-2025-55732 Frappe has the possibility of SQL Injection due to improper validations CWE-89 7.5AI High AI 2025-08-20
CVE-2025-55731 Frappe has the possibility of Authenticated SQL Injection due to improper validations CWE-89 7.5AI High AI 2025-08-20
CVE-2025-52898 Frappe account takeover via password reset token leakage CWE-200 9.1AI Critical AI 2025-06-30
CVE-2025-52896 Frappe authenticated XSS via data import CWE-79 5.4AI Medium AI 2025-06-30
CVE-2025-52895 Frappe possibility of SQL injection due to improper validations CWE-89 7.5AI High AI 2025-06-30
CVE-2025-30217 Frappe has possibility of SQL injection due to improper validations CWE-89 7.5AI High AI 2025-03-26
CVE-2025-30214 Frappe vulnerable to information disclosure leading to account takeover CWE-200 8.1AI High AI 2025-03-25
CVE-2025-30213 Frappe has Possibility of Remote Code Execution due to improper validation CWE-20 8.8AI High AI 2025-03-25
CVE-2025-30212 Frappe has possibility of SQL injection due to improper validations CWE-89 7.5AI High AI 2025-03-25
CVE-2024-34074 Frappe vuilnerable to an open redirect on login page CWE-601 6.1 Medium 2024-05-09

All 70 known CVE vulnerabilities affecting frappe with full Chinese analysis, references, and POCs where available.