Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

frappe — Vulnerabilities & Security Advisories 149

Browse all 149 CVE security advisories affecting frappe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Frappe is an open-source web framework primarily utilized for building enterprise resource planning (ERP) applications, most notably through its flagship product, ERPNext. With seventy recorded Common Vulnerabilities and Exposures, the platform has faced significant scrutiny regarding its security posture. Historically, the most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection, often stemming from insufficient input validation or improper access controls within custom modules. Privilege escalation flaws have also been documented, allowing unauthorized users to gain elevated permissions. While the core framework itself receives regular updates, the extensive ecosystem of third-party apps introduces variability in security hygiene. Major incidents have largely involved misconfigurations or exploited bugs in specific integrations rather than fundamental architectural failures, highlighting the critical importance of rigorous patch management and secure coding practices for developers extending the Frappe platform.

CVE ID Title CVSS Severity Published
CVE-2026-101006 Frappe HR Permission Validation __init__.py get_attendance_requests authorization — HR CWE-863 4.3 Medium 2026-09-28
CVE-2026-96672 Frappe ERPNext before 16.34.1 Unauthorized Method Invocation — ERPNext CWE-470 6.4 Medium 2026-09-23
CVE-2026-94113 Frappe ERPNext before 15.121.0 and 16.34.0 Missing Authorization in Timesheet Endpoints — ERPNext CWE-862 6.5 Medium 2026-09-20
CVE-2026-54343 Frappe LMS: Path Traversal in SCORM File Serving — lms CWE-22 8.7 High 2026-09-17
CVE-2026-54524 Frappe HR: SQL Injection in HRMS Salary Payments Based on Payment Mode Report — hrms CWE-89 7.1 High 2026-09-17
CVE-2023-51769 Frappe 跨站脚本漏洞 — Frappe CWE-79 6.1 Medium 2026-09-14
CVE-2026-53761 Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api — crm CWE-287 8.2 High 2026-09-04
CVE-2026-82634 Frappe Framework Development Branch Incorrect Authorization via Jinja Template Preview Endpoint — frappe CWE-863 6.5 Medium 2026-08-30
CVE-2026-81731 Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description — frappe CWE-79 5.4 Medium 2026-08-27
CVE-2026-66003 Frappe: Access control bypass via REST API dot-notation fields on linked doctypes — frappe CWE-863 7.1 High 2026-08-26
CVE-2026-66002 Frappe: User Enumeration via PDDR — frappe CWE-204 6.9 Medium 2026-08-20
CVE-2026-66001 Frappe: Improper Authorization in OAuth2 Consent Endpoint — frappe CWE-352 8.5 High 2026-08-20
CVE-2026-62315 Frappe: Mass assignment via set_value — frappe CWE-915 7.1 High 2026-08-20
CVE-2026-63654 Frappe: Unauthenticated Workflow approval via confirm_action — frappe CWE-352 6.9 Medium 2026-08-20
CVE-2026-53569 Frappe: Missing authorization in toggle_like and mark_as_seen — frappe CWE-862 5.3 Medium 2026-08-20
CVE-2026-65822 ERPNext: SQL Injection in "Inactive Customers" report via unvalidated `doctype` filter — erpnext CWE-89 7.6 High 2026-08-17
CVE-2026-65974 ERPNext: Server-Side Template Injection leading to Remote Code Execution — erpnext CWE-1336 9.9 Critical 2026-08-17
CVE-2026-72911 ERPNext: Possibility of server-side template injection due to missing validation — erpnext CWE-1336 9.9 Critical 2026-08-10
CVE-2026-72910 ERPNext: Unauthorised modification of master data due to missing validation — erpnext CWE-862 7.1 High 2026-08-10
CVE-2026-72909 ERPNext: Broken Access Control on certain endpoints — erpnext CWE-284 7.1 High 2026-08-10
CVE-2026-72908 ERPNext: Possibility of SQL injection due to missing validation — erpnext CWE-89 6.5 Medium 2026-08-10
CVE-2026-72907 ERPNext: Broken Access Control on certain endpoint — erpnext CWE-285 6.5 Medium 2026-08-10
CVE-2026-72906 ERPNext: Unauthorised triggering of automated emails due to missing validation — erpnext CWE-862 4.3 Medium 2026-08-10
CVE-2026-66000 Frappe: Unrestricted access to Document Follow APIs — frappe CWE-863 2.3 Low 2026-08-07
CVE-2025-58375 Frappe has potential SQL Injection due to missing validation — frappe CWE-89 8.1 High 2026-08-07
CVE-2026-66058 Frappe: Unrestricted access to a Document Follow API — frappe CWE-862 5.3 Medium 2026-08-07
CVE-2026-66059 Frappe: Field-level permission bypass via Document Follow — frappe CWE-863 5.3 Medium 2026-08-07
CVE-2026-49391 Frappe: Stored XSS in Column Headers via Data Import — frappe CWE-79 5.1 Medium 2026-08-06
CVE-2026-47765 Frappe: Lack of Permissions in restore/bulk_restore — frappe CWE-862 7.1 High 2026-08-06
CVE-2026-47194 Frappe: Host header poisoning can redirect magic login links to an attacker-controlled domain — frappe CWE-346 8.6 High 2026-08-06

This page lists every published CVE security advisory associated with frappe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.