Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

frappe — Vulnerabilities & Security Advisories 149

Browse all 149 CVE security advisories affecting frappe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Frappe is an open-source web framework primarily utilized for building enterprise resource planning (ERP) applications, most notably through its flagship product, ERPNext. With seventy recorded Common Vulnerabilities and Exposures, the platform has faced significant scrutiny regarding its security posture. Historically, the most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection, often stemming from insufficient input validation or improper access controls within custom modules. Privilege escalation flaws have also been documented, allowing unauthorized users to gain elevated permissions. While the core framework itself receives regular updates, the extensive ecosystem of third-party apps introduces variability in security hygiene. Major incidents have largely involved misconfigurations or exploited bugs in specific integrations rather than fundamental architectural failures, highlighting the critical importance of rigorous patch management and secure coding practices for developers extending the Frappe platform.

Found 12 results / 149 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-50712 Frappe Framework 17.0.0-dev - Stored XSS in Tree View node label rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50711 Frappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50710 Frappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_config — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50709 Frappe Framework 17.0.0-dev - Stored XSS in Notifications Events color rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50708 Frappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50705 Frappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50704 Frappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50703 Frappe Framework 17.0.0-dev - Stored XSS in Desktop Icon label rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50701 Frappe Framework 17.0.0-dev - Reflected DOM XSS in dashboard-view breadcrumb rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50700 Frappe Framework 17.0.0-dev - Stored XSS in frappe.get_avatar image rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50699 Frappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule rendering — Frappe Framework CWE-79 - - 2026-06-24
CVE-2026-50698 Frappe Framework 17.0.0-dev - Stored XSS in Audit Trail template rendering — Frappe Framework CWE-79 - - 2026-06-24

This page lists every published CVE security advisory associated with frappe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.