Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

frappe — Vulnerabilities & Security Advisories 149

Browse all 149 CVE security advisories affecting frappe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Frappe is an open-source web framework primarily utilized for building enterprise resource planning (ERP) applications, most notably through its flagship product, ERPNext. With seventy recorded Common Vulnerabilities and Exposures, the platform has faced significant scrutiny regarding its security posture. Historically, the most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection, often stemming from insufficient input validation or improper access controls within custom modules. Privilege escalation flaws have also been documented, allowing unauthorized users to gain elevated permissions. While the core framework itself receives regular updates, the extensive ecosystem of third-party apps introduces variability in security hygiene. Major incidents have largely involved misconfigurations or exploited bugs in specific integrations rather than fundamental architectural failures, highlighting the critical importance of rigorous patch management and secure coding practices for developers extending the Frappe platform.

Found 25 results / 149 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-96672 Frappe ERPNext before 16.34.1 Unauthorized Method Invocation — ERPNext CWE-470 6.4 Medium 2026-09-23
CVE-2026-94113 Frappe ERPNext before 15.121.0 and 16.34.0 Missing Authorization in Timesheet Endpoints — ERPNext CWE-862 6.5 Medium 2026-09-20
CVE-2026-65822 ERPNext: SQL Injection in "Inactive Customers" report via unvalidated `doctype` filter — erpnext CWE-89 7.6 High 2026-08-17
CVE-2026-65974 ERPNext: Server-Side Template Injection leading to Remote Code Execution — erpnext CWE-1336 9.9 Critical 2026-08-17
CVE-2026-72911 ERPNext: Possibility of server-side template injection due to missing validation — erpnext CWE-1336 9.9 Critical 2026-08-10
CVE-2026-72910 ERPNext: Unauthorised modification of master data due to missing validation — erpnext CWE-862 7.1 High 2026-08-10
CVE-2026-72909 ERPNext: Broken Access Control on certain endpoints — erpnext CWE-284 7.1 High 2026-08-10
CVE-2026-72908 ERPNext: Possibility of SQL injection due to missing validation — erpnext CWE-89 6.5 Medium 2026-08-10
CVE-2026-72907 ERPNext: Broken Access Control on certain endpoint — erpnext CWE-285 6.5 Medium 2026-08-10
CVE-2026-72906 ERPNext: Unauthorised triggering of automated emails due to missing validation — erpnext CWE-862 4.3 Medium 2026-08-10
CVE-2026-13227 ERPNext v16.25.0 - Improper authorization in Prospect opportunities API — ERPNext CWE-862 7.1 High 2026-08-04
CVE-2026-12895 SQL Injection in Frappe's ERPNext — ERPNext CWE-89 7.1 High 2026-07-29
CVE-2026-55242 ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefix — erpnext CWE-863 8.8 High 2026-07-15
CVE-2026-42839 ERPNext 16.16.0 - Stored XSS in POS cart item rendering — ERPNext CWE-79 - - 2026-06-03
CVE-2026-42840 ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals — ERPNext CWE-79 - - 2026-06-03
CVE-2026-44448 ERPNext: Unauthorised Document modification due to missing validation — erpnext CWE-862 5.9 Medium 2026-05-13
CVE-2026-44447 ERPNext: Possibility of SQL Injection due to missing validation — erpnext CWE-89 8.8 High 2026-05-13
CVE-2026-44446 ERPNext: Possibility of SQL Injection due to missing validation — erpnext CWE-89 8.8 High 2026-05-13
CVE-2026-44445 ERPNext: XML External Entity (XEE) Reference Vulnerability in the EDI Module — erpnext CWE-611 - - 2026-05-13
CVE-2026-44441 ERPNext: Possible SSRF by any authenticated user — erpnext CWE-918 5.0 Medium 2026-05-13
CVE-2026-44440 ERPNext: Path Traversal Leading to Sensitive File Exposure — erpnext CWE-22 6.5 Medium 2026-05-13
CVE-2026-44442 ERPNext: Unauthorised Document modification due to missing validation — erpnext CWE-862 9.9 Critical 2026-05-13
CVE-2026-32954 ERP has a possibility SQL Injection vulnerability due to missing validation — erpnext CWE-89 7.1 High 2026-03-20
CVE-2026-27471 ERP: Document access through endpoints due to missing validation — erpnext CWE-862 4.3AI Medium AI 2026-02-21
CVE-2025-58439 ERP: Possibility of SQL injection due to missing validation — erpnext CWE-89 8.1 High 2025-09-06

This page lists every published CVE security advisory associated with frappe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.