Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

frappe — Vulnerabilities & Security Advisories 149

Browse all 149 CVE security advisories affecting frappe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Frappe is an open-source web framework primarily utilized for building enterprise resource planning (ERP) applications, most notably through its flagship product, ERPNext. With seventy recorded Common Vulnerabilities and Exposures, the platform has faced significant scrutiny regarding its security posture. Historically, the most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection, often stemming from insufficient input validation or improper access controls within custom modules. Privilege escalation flaws have also been documented, allowing unauthorized users to gain elevated permissions. While the core framework itself receives regular updates, the extensive ecosystem of third-party apps introduces variability in security hygiene. Major incidents have largely involved misconfigurations or exploited bugs in specific integrations rather than fundamental architectural failures, highlighting the critical importance of rigorous patch management and secure coding practices for developers extending the Frappe platform.

CVE ID Title CVSS Severity Published
CVE-2026-47185 Frappe Has Broken Access Control in its Workspace Save API — frappe CWE-863 5.1 Medium 2026-08-06
CVE-2026-13227 ERPNext v16.25.0 - Improper authorization in Prospect opportunities API — ERPNext CWE-862 7.1 High 2026-08-04
CVE-2026-12895 SQL Injection in Frappe's ERPNext — ERPNext CWE-89 7.1 High 2026-07-29
CVE-2026-39385 Frappe LMS enrollment bypass in paid courses via unrelated batch — lms CWE-288 - - 2026-07-20
CVE-2026-55242 ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefix — erpnext CWE-863 8.8 High 2026-07-15
CVE-2026-55852 Frappe: TarSlip RCE in Package Import — frappe CWE-22 - - 2026-07-10
CVE-2026-42219 Frappe: Path Traversal via /backups Route — frappe CWE-22 - - 2026-07-10
CVE-2026-49394 Frappe: Auth. bypass via update_page — frappe CWE-862 - - 2026-07-10
CVE-2026-48127 Frappe: Arbitrary Attachment Injection via add_attachments and upload_file — frappe CWE-862 - - 2026-07-10
CVE-2026-41482 Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Generator — frappe CWE-22 - - 2026-07-10
CVE-2026-47199 Frappe: check_safe_sql_query Permits SELECT INTO OUTFILE — frappe CWE-89 - - 2026-07-10
CVE-2026-58503 Frappe: Unauthenticated User Enumeration via reset_password — frappe CWE-203 - - 2026-07-10
CVE-2026-47422 Frappe: Unrestricted API access to save_report — frappe CWE-862 - - 2026-07-10
CVE-2026-50712 Frappe Framework 17.0.0-dev - Stored XSS in Tree View node label rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50711 Frappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50710 Frappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_config — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50709 Frappe Framework 17.0.0-dev - Stored XSS in Notifications Events color rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50708 Frappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50705 Frappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50704 Frappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50703 Frappe Framework 17.0.0-dev - Stored XSS in Desktop Icon label rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50701 Frappe Framework 17.0.0-dev - Reflected DOM XSS in dashboard-view breadcrumb rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50700 Frappe Framework 17.0.0-dev - Stored XSS in frappe.get_avatar image rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50699 Frappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50698 Frappe Framework 17.0.0-dev - Stored XSS in Audit Trail template rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-53568 Frappe: Stored XSS in Frappe Report/List View via 'set_link_title_field_value' — frappe CWE-79 - - 2026-06-12
CVE-2026-50026 Frappe: Lack of permissions checks in 'relink' and 'set_email_password' endpoints — frappe CWE-862 - - 2026-06-12
CVE-2026-47182 Frappe: Broken Access Control on Private Files — frappe CWE-284 - - 2026-06-12
CVE-2026-44976 Frappe: IDOR in update_onboarding_step — frappe CWE-284 - - 2026-06-12
CVE-2026-44975 Frappe: Missing authorization on reset form tours — frappe CWE-862 - - 2026-06-12

This page lists every published CVE security advisory associated with frappe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.