Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

frappe — Vulnerabilities & Security Advisories 149

Browse all 149 CVE security advisories affecting frappe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Frappe is an open-source web framework primarily utilized for building enterprise resource planning (ERP) applications, most notably through its flagship product, ERPNext. With seventy recorded Common Vulnerabilities and Exposures, the platform has faced significant scrutiny regarding its security posture. Historically, the most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection, often stemming from insufficient input validation or improper access controls within custom modules. Privilege escalation flaws have also been documented, allowing unauthorized users to gain elevated permissions. While the core framework itself receives regular updates, the extensive ecosystem of third-party apps introduces variability in security hygiene. Major incidents have largely involved misconfigurations or exploited bugs in specific integrations rather than fundamental architectural failures, highlighting the critical importance of rigorous patch management and secure coding practices for developers extending the Frappe platform.

CVE ID Title CVSS Severity Published
CVE-2025-11281 Frappe LMS Unpublished Course courses access control — LMS CWE-284 5.0 Medium 2025-10-05
CVE-2025-11280 Frappe LMS Assignment Picture files direct request — LMS CWE-425 3.7 Low 2025-10-05
CVE-2025-59421 Press vulnerable to email flooding to users due to lack of validation and rate limits — press CWE-770 - - AI 2025-09-18
CVE-2025-59415 Frappe Learning vulnerable to Malicious Content upload via Profile bio field — lms CWE-79 4.6 Medium 2025-09-17
CVE-2025-58439 ERP: Possibility of SQL injection due to missing validation — erpnext CWE-89 8.1 High 2025-09-06
CVE-2025-55732 Frappe has the possibility of SQL Injection due to improper validations — frappe CWE-89 7.5AI High AI 2025-08-20
CVE-2025-55731 Frappe has the possibility of Authenticated SQL Injection due to improper validations — frappe CWE-89 7.5AI High AI 2025-08-20
CVE-2025-55006 Frappe Learning Holds Potential for Malicious SVG Upload in Image Upload Feature — lms CWE-20 4.3 Medium 2025-08-09
CVE-2025-53545 Press has a potential 2FA bypass — press CWE-287 9.8AI Critical AI 2025-07-08
CVE-2025-52898 Frappe account takeover via password reset token leakage — frappe CWE-200 9.1AI Critical AI 2025-06-30
CVE-2025-52896 Frappe authenticated XSS via data import — frappe CWE-79 5.4AI Medium AI 2025-06-30
CVE-2025-52895 Frappe possibility of SQL injection due to improper validations — frappe CWE-89 7.5AI High AI 2025-06-30
CVE-2025-30217 Frappe has possibility of SQL injection due to improper validations — frappe CWE-89 7.5AI High AI 2025-03-26
CVE-2025-30214 Frappe vulnerable to information disclosure leading to account takeover — frappe CWE-200 8.1AI High AI 2025-03-25
CVE-2025-30213 Frappe has Possibility of Remote Code Execution due to improper validation — frappe CWE-20 8.8AI High AI 2025-03-25
CVE-2025-30212 Frappe has possibility of SQL injection due to improper validations — frappe CWE-89 7.5AI High AI 2025-03-25
CVE-2024-50356 Press has a potential 2FA bypass — press CWE-640 - - 2024-10-31
CVE-2024-49751 Frappe Press possible HTML injection through SaaS Signup inputs — press CWE-79 5.4AI Medium AI 2024-10-23
CVE-2024-34074 Frappe vuilnerable to an open redirect on login page — frappe CWE-601 6.1 Medium 2024-05-09
CVE-2024-27105 Frappe File Permissions can by bypassed using certain endpoints — frappe CWE-863 8.1 High 2024-03-20
CVE-2024-24813 Frappe SQL Injection from reporting logic — frappe CWE-89 7.5 High 2024-03-20
CVE-2024-24812 Frappe Authenticated Reflected Cross site scripting (XSS) in portal pages — frappe CWE-79 5.4 Medium 2024-02-07
CVE-2023-46127 Frappe vulnerable to HTML injection by any Desk user — frappe CWE-79 5.4 Medium 2023-10-23
CVE-2023-5555 Cross-site Scripting (XSS) - Generic in frappe/lms — frappe/lms CWE-79 6.1 - 2023-10-12
CVE-2023-42807 Frappe LMS SQL Injection Issue on People Page — lms CWE-89 6.3 Medium 2023-09-21
CVE-2023-41328 Possibility limited SQL injection due to insufficient validation in Frappe — frappe CWE-89 4.2 Medium 2023-09-06
CVE-2022-23055 ERPNext - Improper user access conrol — frappe CWE-862 8.1 - 2022-06-22
CVE-2022-23058 ERPNext - Stored XSS in My Settings — frappe CWE-79 5.4 - 2022-06-22
CVE-2022-23057 ERPNext - Stored XSS in My Profile — frappe CWE-79 5.4 - 2022-06-22

This page lists every published CVE security advisory associated with frappe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.