Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

frappe — Vulnerabilities & Security Advisories 149

Browse all 149 CVE security advisories affecting frappe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Frappe is an open-source web framework primarily utilized for building enterprise resource planning (ERP) applications, most notably through its flagship product, ERPNext. With seventy recorded Common Vulnerabilities and Exposures, the platform has faced significant scrutiny regarding its security posture. Historically, the most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection, often stemming from insufficient input validation or improper access controls within custom modules. Privilege escalation flaws have also been documented, allowing unauthorized users to gain elevated permissions. While the core framework itself receives regular updates, the extensive ecosystem of third-party apps introduces variability in security hygiene. Major incidents have largely involved misconfigurations or exploited bugs in specific integrations rather than fundamental architectural failures, highlighting the critical importance of rigorous patch management and secure coding practices for developers extending the Frappe platform.

CVE ID Title CVSS Severity Published
CVE-2026-32954 ERP has a possibility SQL Injection vulnerability due to missing validation — erpnext CWE-89 7.1 High 2026-03-20
CVE-2026-31879 Frappe Workspace modification and stored XSS due to improper resource ownership checks — frappe CWE-79 5.4AI Medium AI 2026-03-11
CVE-2026-31878 Frappe: Possible SSRF by any authenticated user — frappe CWE-918 5.0 Medium 2026-03-11
CVE-2026-31877 Frappe SQL Injection due to improper field sanitization — frappe CWE-89 7.5AI High AI 2026-03-11
CVE-2026-29081 Frappe: Possibility of SQL Injection due to improper fieldname sanitization — frappe CWE-89 6.5 Medium 2026-03-05
CVE-2026-29077 Frappe: Broken Access Control in DocShare — frappe CWE-284 7.1 High 2026-03-05
CVE-2026-28436 Frappe: Stored XSS in avatar_macro.html — frappe CWE-79 5.4 - 2026-03-05
CVE-2026-27471 ERP: Document access through endpoints due to missing validation — erpnext CWE-862 4.3AI Medium AI 2026-02-21
CVE-2026-26977 Frappe Learning Management System exposes details of unpublished courses to unauthorized users — lms CWE-862 4.3 - 2026-02-20
CVE-2026-26031 Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled students — lms CWE-863 5.3AI Medium AI 2026-02-11
CVE-2026-25956 Frappe Affected by XSS and Open Redirect in Sign Up — frappe CWE-601 6.1 Medium 2026-02-10
CVE-2026-23497 Frappe LMS has a Stored XSS via Unsanitized Image Filename in Course and Jobs Pages — lms CWE-79 5.4AI Medium AI 2026-01-14
CVE-2025-68953 Certain Frappe requests are vulnerable to Path Traversal — frappe CWE-22 7.5 High 2026-01-05
CVE-2025-68929 Frappe may be vulnerable remote code execution due to server-side template injection — frappe CWE-1336 9.1 Critical 2025-12-29
CVE-2025-68928 Frappe CRM vulnerable to authenticated XSS via website field — crm CWE-79 5.4 Medium 2025-12-29
CVE-2025-67734 Frappe Authenticated Users can Execute JavaScript through its Job Form — lms CWE-79 5.4AI Medium AI 2025-12-12
CVE-2025-67730 Frappe authenticated users can execute XSS through form description fields — lms CWE-79 5.4AI Medium AI 2025-12-12
CVE-2025-10655 Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data — Frappe HelpDesk CWE-89 8.8AI High AI 2025-12-09
CVE-2025-66581 Frappe LMS is Missing Server-Side Authorization in Business Logic — lms CWE-863 8.8 - 2025-12-05
CVE-2025-66206 Frappe vulnerable to a path traversal allowing reading certain files — frappe CWE-22 6.8 Medium 2025-12-01
CVE-2025-66205 Frappe has the possibility of SQL Injection due to improper validations — frappe CWE-89 7.1 High 2025-12-01
CVE-2025-11461 Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard Controller — Frappe CRM CWE-89 8.8AI High AI 2025-11-26
CVE-2025-64707 Frappe LMS revoking access did not show immediate effect as roles were cached — lms CWE-863 6.3 - 2025-11-12
CVE-2025-64705 Frappe user was able to access the submission of other students — lms CWE-200 4.6 - 2025-11-12
CVE-2025-62779 Frappe Learning users were able to add HTML through input fields in the Job Form — lms CWE-79 5.4AI Medium AI 2025-10-27
CVE-2025-62778 Frappe Learning allowed students to access the Quiz Form via direct URL — lms CWE-425 5.3AI Medium AI 2025-10-27
CVE-2025-62407 Frappe has an Open Redirect on Login Page — frappe CWE-601 6.1 Medium 2025-10-16
CVE-2025-62158 Frappe had attachments made by students to their assignments of type Text set to public — lms CWE-200 7.5AI High AI 2025-10-10
CVE-2025-11283 Frappe LMS Course cross site scripting — LMS CWE-79 2.4 Low 2025-10-05
CVE-2025-11282 Frappe LMS Incomplete Fix CVE-2025-55006 cross site scripting — LMS CWE-79 2.4 Low 2025-10-05

This page lists every published CVE security advisory associated with frappe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.