Exposure of Frappe

Web frameworks
60
exposure score
539
sites use
0
exploited
3
critical

CVEs

73 results
CVE-2023-41328MEDIUMPossibility limited SQL injection due to insufficient validation in FrappeEPSS 0.5%CVE-2026-62315HIGHFrappe: Mass assignment via set_valueEPSS 0.5%CVE-2026-66059MEDIUMFrappe: Field-level permission bypass via Document FollowEPSS 0.5%CVE-2026-31877CRITICALFrappe SQL Injection due to improper field sanitizationEPSS 0.5%CVE-2026-35614CRITICALFrappe has a SQL injection in bulk_updateEPSS 0.5%CVE-2026-49391MEDIUMFrappe: Stored XSS in Column Headers via Data ImportEPSS 0.5%CVE-2026-29081MEDIUMFrappe: Possibility of SQL Injection due to improper fieldname sanitizationEPSS 0.5%CVE-2026-53569MEDIUMFrappe: Missing authorization in toggle_like and mark_as_seenEPSS 0.5%CVE-2026-47765HIGHFrappe: Lack of Permissions in restore/bulk_restoreEPSS 0.4%CVE-2026-66000LOWFrappe: Unrestricted access to Document Follow APIsEPSS 0.4%CVE-2025-52898HIGHFrappe account takeover via password reset token leakageEPSS 0.4%CVE-2026-44207MEDIUMFrappe: Insecure Direct Object Reference for email accountsEPSS 0.4%CVE-2026-44208MEDIUMFrappe: IDOR in `submit_discussion()`EPSS 0.4%CVE-2026-50026MEDIUMFrappe: Lack of permissions checks in 'relink' and 'set_email_password' endpointsEPSS 0.4%CVE-2026-39351MEDIUMFrappe allows unrestricted Doctype access via API exploitEPSS 0.4%CVE-2026-44205MEDIUMFrappe: Stored Cross-Site Scripting (XSS) in User Profile through Image UploadEPSS 0.4%CVE-2026-47739MEDIUMFrappe: Stored XSS in NoteEPSS 0.4%CVE-2026-53568MEDIUMFrappe: Stored XSS in Frappe Report/List View via 'set_link_title_field_value'EPSS 0.4%CVE-2025-30212MEDIUMFrappe has possibility of SQL injection due to improper validationsEPSS 0.4%CVE-2025-68953HIGHCertain Frappe requests are vulnerable to Path TraversalEPSS 0.4%