All 70 CVE vulnerabilities found in frappe, with AI-generated Chinese analysis, references, and POCs.
This page aggregates known vulnerabilities for the frappe framework, covering common weakness types and associated security tags. It collects data regarding critical flaws, code injection risks, and authentication bypasses that have been identified within the ecosystem over the past five years. By centralizing this information, the page allows users to track vendor advisories from the official maintainers, understand the prevalence and impact of specific weakness classes across different modules, and look up the complete vulnerability history of the product to assess long-term security posture. The content includes details on affected versions, severity ratings, and available patches, providing a comprehensive view of the threat landscape for frappe applications. This resource is designed for security analysts, developers, and system administrators who need to make informed decisions about patching and mitigation strategies. It does not offer real-time monitoring or automated threat detection services, but rather serves as a static reference for historical and current known issues. Users are encouraged to cross-reference this data with official vendor bulletins and independent security research for the most up-to-date guidance on remediation.
Vendor: frappe
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-27105 | Frappe File Permissions can by bypassed using certain endpoints CWE-863 | 8.1 | High | 2024-03-20 |
| CVE-2024-24813 | Frappe SQL Injection from reporting logic CWE-89 | 7.5 | High | 2024-03-20 |
| CVE-2024-24812 | Frappe Authenticated Reflected Cross site scripting (XSS) in portal pages CWE-79 | 5.4 | Medium | 2024-02-07 |
| CVE-2023-46127 | Frappe vulnerable to HTML injection by any Desk user CWE-79 | 5.4 | Medium | 2023-10-23 |
| CVE-2023-41328 | Possibility limited SQL injection due to insufficient validation in Frappe CWE-89 | 4.2 | Medium | 2023-09-06 |
| CVE-2022-41712 | Frappe Technologies Frappe 路径遍历漏洞 | 6.3 | - | 2022-11-25 |
| CVE-2022-3988 | Frappe Search navbar_search.html cross site scripting CWE-707 | 3.5 | Low | 2022-11-14 |
| CVE-2022-23055 | ERPNext - Improper user access conrol CWE-862 | 8.1 | - | 2022-06-22 |
| CVE-2022-23058 | ERPNext - Stored XSS in My Settings CWE-79 | 5.4 | - | 2022-06-22 |
| CVE-2022-23057 | ERPNext - Stored XSS in My Profile CWE-79 | 5.4 | - | 2022-06-22 |
All 70 known CVE vulnerabilities affecting frappe with full Chinese analysis, references, and POCs where available.