Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

frappe — Vulnerabilities & Security Advisories 149

Browse all 149 CVE security advisories affecting frappe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Frappe is an open-source web framework primarily utilized for building enterprise resource planning (ERP) applications, most notably through its flagship product, ERPNext. With seventy recorded Common Vulnerabilities and Exposures, the platform has faced significant scrutiny regarding its security posture. Historically, the most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection, often stemming from insufficient input validation or improper access controls within custom modules. Privilege escalation flaws have also been documented, allowing unauthorized users to gain elevated permissions. While the core framework itself receives regular updates, the extensive ecosystem of third-party apps introduces variability in security hygiene. Major incidents have largely involved misconfigurations or exploited bugs in specific integrations rather than fundamental architectural failures, highlighting the critical importance of rigorous patch management and secure coding practices for developers extending the Frappe platform.

Found 71 results / 149 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2023-51769 Frappe 跨站脚本漏洞 — Frappe CWE-79 6.1 Medium 2026-09-14
CVE-2026-82634 Frappe Framework Development Branch Incorrect Authorization via Jinja Template Preview Endpoint — frappe CWE-863 6.5 Medium 2026-08-30
CVE-2026-81731 Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description — frappe CWE-79 5.4 Medium 2026-08-27
CVE-2026-66003 Frappe: Access control bypass via REST API dot-notation fields on linked doctypes — frappe CWE-863 7.1 High 2026-08-26
CVE-2026-66002 Frappe: User Enumeration via PDDR — frappe CWE-204 6.9 Medium 2026-08-20
CVE-2026-66001 Frappe: Improper Authorization in OAuth2 Consent Endpoint — frappe CWE-352 8.5 High 2026-08-20
CVE-2026-62315 Frappe: Mass assignment via set_value — frappe CWE-915 7.1 High 2026-08-20
CVE-2026-63654 Frappe: Unauthenticated Workflow approval via confirm_action — frappe CWE-352 6.9 Medium 2026-08-20
CVE-2026-53569 Frappe: Missing authorization in toggle_like and mark_as_seen — frappe CWE-862 5.3 Medium 2026-08-20
CVE-2026-66000 Frappe: Unrestricted access to Document Follow APIs — frappe CWE-863 2.3 Low 2026-08-07
CVE-2025-58375 Frappe has potential SQL Injection due to missing validation — frappe CWE-89 8.1 High 2026-08-07
CVE-2026-66058 Frappe: Unrestricted access to a Document Follow API — frappe CWE-862 5.3 Medium 2026-08-07
CVE-2026-66059 Frappe: Field-level permission bypass via Document Follow — frappe CWE-863 5.3 Medium 2026-08-07
CVE-2026-49391 Frappe: Stored XSS in Column Headers via Data Import — frappe CWE-79 5.1 Medium 2026-08-06
CVE-2026-47765 Frappe: Lack of Permissions in restore/bulk_restore — frappe CWE-862 7.1 High 2026-08-06
CVE-2026-47194 Frappe: Host header poisoning can redirect magic login links to an attacker-controlled domain — frappe CWE-346 8.6 High 2026-08-06
CVE-2026-47185 Frappe Has Broken Access Control in its Workspace Save API — frappe CWE-863 5.1 Medium 2026-08-06
CVE-2026-55852 Frappe: TarSlip RCE in Package Import — frappe CWE-22 - - 2026-07-10
CVE-2026-42219 Frappe: Path Traversal via /backups Route — frappe CWE-22 - - 2026-07-10
CVE-2026-49394 Frappe: Auth. bypass via update_page — frappe CWE-862 - - 2026-07-10
CVE-2026-48127 Frappe: Arbitrary Attachment Injection via add_attachments and upload_file — frappe CWE-862 - - 2026-07-10
CVE-2026-41482 Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Generator — frappe CWE-22 - - 2026-07-10
CVE-2026-47199 Frappe: check_safe_sql_query Permits SELECT INTO OUTFILE — frappe CWE-89 - - 2026-07-10
CVE-2026-58503 Frappe: Unauthenticated User Enumeration via reset_password — frappe CWE-203 - - 2026-07-10
CVE-2026-47422 Frappe: Unrestricted API access to save_report — frappe CWE-862 - - 2026-07-10
CVE-2026-53568 Frappe: Stored XSS in Frappe Report/List View via 'set_link_title_field_value' — frappe CWE-79 - - 2026-06-12
CVE-2026-50026 Frappe: Lack of permissions checks in 'relink' and 'set_email_password' endpoints — frappe CWE-862 - - 2026-06-12
CVE-2026-47182 Frappe: Broken Access Control on Private Files — frappe CWE-284 - - 2026-06-12
CVE-2026-44976 Frappe: IDOR in update_onboarding_step — frappe CWE-284 - - 2026-06-12
CVE-2026-44975 Frappe: Missing authorization on reset form tours — frappe CWE-862 - - 2026-06-12

This page lists every published CVE security advisory associated with frappe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.