Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

frappe — Vulnerabilities & Security Advisories 132

Browse all 132 CVE security advisories affecting frappe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Frappe is an open-source web framework primarily utilized for building enterprise resource planning (ERP) applications, most notably through its flagship product, ERPNext. With seventy recorded Common Vulnerabilities and Exposures, the platform has faced significant scrutiny regarding its security posture. Historically, the most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection, often stemming from insufficient input validation or improper access controls within custom modules. Privilege escalation flaws have also been documented, allowing unauthorized users to gain elevated permissions. While the core framework itself receives regular updates, the extensive ecosystem of third-party apps introduces variability in security hygiene. Major incidents have largely involved misconfigurations or exploited bugs in specific integrations rather than fundamental architectural failures, highlighting the critical importance of rigorous patch management and secure coding practices for developers extending the Frappe platform.

Found 62 results / 132Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-66000 Frappe: Unrestricted access to Document Follow APIs — frappeCWE-863 2.3 Low2026-08-07
CVE-2025-58375 Frappe has potential SQL Injection due to missing validation — frappeCWE-89 8.1 High2026-08-07
CVE-2026-66058 Frappe: Unrestricted access to a Document Follow API — frappeCWE-862 5.3 Medium2026-08-07
CVE-2026-66059 Frappe: Field-level permission bypass via Document Follow — frappeCWE-863 5.3 Medium2026-08-07
CVE-2026-49391 Frappe: Stored XSS in Column Headers via Data Import — frappeCWE-79 5.1 Medium2026-08-06
CVE-2026-47765 Frappe: Lack of Permissions in restore/bulk_restore — frappeCWE-862 7.1 High2026-08-06
CVE-2026-47194 Frappe: Host header poisoning can redirect magic login links to an attacker-controlled domain — frappeCWE-346 8.6 High2026-08-06
CVE-2026-47185 Frappe Has Broken Access Control in its Workspace Save API — frappeCWE-863 5.1 Medium2026-08-06
CVE-2026-55852 Frappe: TarSlip RCE in Package Import — frappeCWE-22--2026-07-10
CVE-2026-42219 Frappe: Path Traversal via /backups Route — frappeCWE-22--2026-07-10
CVE-2026-49394 Frappe: Auth. bypass via update_page — frappeCWE-862--2026-07-10
CVE-2026-48127 Frappe: Arbitrary Attachment Injection via add_attachments and upload_file — frappeCWE-862--2026-07-10
CVE-2026-41482 Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Generator — frappeCWE-22--2026-07-10
CVE-2026-47199 Frappe: check_safe_sql_query Permits SELECT INTO OUTFILE — frappeCWE-89--2026-07-10
CVE-2026-58503 Frappe: Unauthenticated User Enumeration via reset_password — frappeCWE-203--2026-07-10
CVE-2026-47422 Frappe: Unrestricted API access to save_report — frappeCWE-862--2026-07-10
CVE-2026-53568 Frappe: Stored XSS in Frappe Report/List View via 'set_link_title_field_value' — frappeCWE-79--2026-06-12
CVE-2026-50026 Frappe: Lack of permissions checks in 'relink' and 'set_email_password' endpoints — frappeCWE-862--2026-06-12
CVE-2026-47182 Frappe: Broken Access Control on Private Files — frappeCWE-284--2026-06-12
CVE-2026-44976 Frappe: IDOR in update_onboarding_step — frappeCWE-284--2026-06-12
CVE-2026-44975 Frappe: Missing authorization on reset form tours — frappeCWE-862--2026-06-12
CVE-2026-44206 Frappe: DB Schema Enumeration via Frappe-Authorization-Source — frappeCWE-200--2026-06-12
CVE-2026-44207 Frappe: Insecure Direct Object Reference for email accounts — frappeCWE-639--2026-06-12
CVE-2026-44208 Frappe: IDOR in `submit_discussion()` — frappeCWE-284--2026-06-12
CVE-2026-44205 Frappe: Stored Cross-Site Scripting (XSS) in User Profile through Image Upload — frappeCWE-79--2026-06-12
CVE-2026-41581 Frappe Vulnerable to Possible SQL Injection via get_blog_list — frappeCWE-89--2026-06-12
CVE-2026-47739 Frappe: Stored XSS in Note — frappeCWE-79--2026-06-12
CVE-2026-39352 Frappe has an Arbitrary File Read via Path Traversal in render_include — frappeCWE-22--2026-05-20
CVE-2026-3837 Frappe Framework 16.10.0 - Stored DOM XSS in Multiple Field Formatters — FrappeCWE-79 5.4AIMediumAI2026-04-22
CVE-2026-3673 Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer — FrappeCWE-79 5.4AIMediumAI2026-04-22

This page lists every published CVE security advisory associated with frappe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.