Exposure of Frappe

Web frameworks
60
exposure score
539
sites use
0
exploited
3
critical

CVEs

73 results
CVE-2023-46127MEDIUMFrappe vulnerable to HTML injection by any Desk userEPSS 37.0%CVE-2026-39352HIGHFrappe has an Arbitrary File Read via Path Traversal in render_includeEPSS 1.3%CVE-2022-23055—ERPNext - Improper user access conrolEPSS 1.2%CVE-2022-41712MEDIUMFrappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does nEPSS 0.9%CVE-2022-23058—ERPNext - Stored XSS in My SettingsEPSS 0.9%CVE-2026-66002MEDIUMFrappe: User Enumeration via PDDREPSS 0.8%CVE-2025-30213MEDIUMFrappe has Possibility of Remote Code Execution due to improper validationEPSS 0.7%CVE-2026-55852HIGHFrappe: TarSlip RCE in Package ImportEPSS 0.7%CVE-2026-42219MEDIUMFrappe: Path Traversal via /backups RouteEPSS 0.7%CVE-2024-24813HIGHFrappe SQL Injection from reporting logicEPSS 0.6%CVE-2022-3988LOWFrappe Search navbar_search.html cross site scriptingEPSS 0.6%CVE-2022-23057—ERPNext - Stored XSS in My ProfileEPSS 0.6%CVE-2026-48127MEDIUMFrappe: Arbitrary Attachment Injection via add_attachments and upload_fileEPSS 0.6%CVE-2026-58503MEDIUMFrappe: Unauthenticated User Enumeration via reset_passwordEPSS 0.6%CVE-2024-27105HIGHFrappe File Permissions can by bypassed using certain endpointsEPSS 0.6%CVE-2024-34074MEDIUMFrappe vuilnerable to an open redirect on login pageEPSS 0.6%CVE-2026-47199LOWFrappe: check_safe_sql_query Permits SELECT INTO OUTFILEEPSS 0.5%CVE-2026-49394HIGHFrappe: Auth. bypass via update_pageEPSS 0.5%CVE-2025-68929CRITICALFrappe may be vulnerable remote code execution due to server-side template injectionEPSS 0.5%CVE-2026-41482HIGHFrappe: Possible Path Traversal and Local File Inclusion via Chrome PDF GeneratorEPSS 0.5%