Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

frappe — Vulnerabilities & Security Advisories 149

Browse all 149 CVE security advisories affecting frappe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Frappe is an open-source web framework primarily utilized for building enterprise resource planning (ERP) applications, most notably through its flagship product, ERPNext. With seventy recorded Common Vulnerabilities and Exposures, the platform has faced significant scrutiny regarding its security posture. Historically, the most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection, often stemming from insufficient input validation or improper access controls within custom modules. Privilege escalation flaws have also been documented, allowing unauthorized users to gain elevated permissions. While the core framework itself receives regular updates, the extensive ecosystem of third-party apps introduces variability in security hygiene. Major incidents have largely involved misconfigurations or exploited bugs in specific integrations rather than fundamental architectural failures, highlighting the critical importance of rigorous patch management and secure coding practices for developers extending the Frappe platform.

CVE ID Title CVSS Severity Published
CVE-2026-44206 Frappe: DB Schema Enumeration via Frappe-Authorization-Source — frappe CWE-200 - - 2026-06-12
CVE-2026-44207 Frappe: Insecure Direct Object Reference for email accounts — frappe CWE-639 - - 2026-06-12
CVE-2026-44208 Frappe: IDOR in `submit_discussion()` — frappe CWE-284 - - 2026-06-12
CVE-2026-44205 Frappe: Stored Cross-Site Scripting (XSS) in User Profile through Image Upload — frappe CWE-79 - - 2026-06-12
CVE-2026-41581 Frappe Vulnerable to Possible SQL Injection via get_blog_list — frappe CWE-89 - - 2026-06-12
CVE-2026-47739 Frappe: Stored XSS in Note — frappe CWE-79 - - 2026-06-12
CVE-2026-46546 Frappe LMS: HTML injection in user-controlled metadata — lms CWE-74 - - 2026-06-09
CVE-2026-42839 ERPNext 16.16.0 - Stored XSS in POS cart item rendering — ERPNext CWE-79 - - 2026-06-03
CVE-2026-42840 ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals — ERPNext CWE-79 - - 2026-06-03
CVE-2026-45081 Frappe HR: Permission Bypass in HRMS Leave Details API — hrms CWE-863 6.5 Medium 2026-05-27
CVE-2026-39405 Frappe has Path Transversal via SCORM — lms CWE-22 - - 2026-05-20
CVE-2026-39352 Frappe has an Arbitrary File Read via Path Traversal in render_include — frappe CWE-22 - - 2026-05-20
CVE-2026-44448 ERPNext: Unauthorised Document modification due to missing validation — erpnext CWE-862 5.9 Medium 2026-05-13
CVE-2026-44447 ERPNext: Possibility of SQL Injection due to missing validation — erpnext CWE-89 8.8 High 2026-05-13
CVE-2026-44446 ERPNext: Possibility of SQL Injection due to missing validation — erpnext CWE-89 8.8 High 2026-05-13
CVE-2026-44445 ERPNext: XML External Entity (XEE) Reference Vulnerability in the EDI Module — erpnext CWE-611 - - 2026-05-13
CVE-2026-44441 ERPNext: Possible SSRF by any authenticated user — erpnext CWE-918 5.0 Medium 2026-05-13
CVE-2026-44440 ERPNext: Path Traversal Leading to Sensitive File Exposure — erpnext CWE-22 6.5 Medium 2026-05-13
CVE-2026-44442 ERPNext: Unauthorised Document modification due to missing validation — erpnext CWE-862 9.9 Critical 2026-05-13
CVE-2026-41430 Press vulnerable to reflected XSS on login redirection — press CWE-79 6.1AI Medium AI 2026-04-24
CVE-2026-41317 Frappe Press has an unsafe HTTP method / CSRF-adjacent issue on API secret generation — press CWE-352 8.8AI High AI 2026-04-24
CVE-2026-3837 Frappe Framework 16.10.0 - Stored DOM XSS in Multiple Field Formatters — Frappe CWE-79 5.4AI Medium AI 2026-04-22
CVE-2026-3673 Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer — Frappe CWE-79 5.4AI Medium AI 2026-04-22
CVE-2026-41320 Frappe HR has possibility of SQL Injection due to improper field sanitization — hrms CWE-89 6.5 Medium 2026-04-21
CVE-2026-40889 Frappe HR has Improper Access Control on Files — hrms CWE-284 6.5 Medium 2026-04-21
CVE-2026-40888 Frappe HR vulnerable to Improper Access Control — hrms CWE-284 6.5AI Medium AI 2026-04-21
CVE-2026-39415 Frappe Learning Management System has Client-Side Manipulation of Quiz Scores — lms CWE-602 7.1AI High AI 2026-04-08
CVE-2026-39351 Frappe allows unrestricted Doctype access via API exploit — frappe CWE-862 8.8AI High AI 2026-04-07
CVE-2026-35614 Frappe has a SQL injection in bulk_update — frappe CWE-89 8.8AI High AI 2026-04-07
CVE-2026-34606 Stored XSS in Frappe LMS — lms CWE-79 5.4AI Medium AI 2026-04-02

This page lists every published CVE security advisory associated with frappe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.