Exposure of Frappe

Web frameworks
60
exposure score
539
sites use
0
exploited
3
critical

CVEs

73 results
CVE-2026-44206MEDIUMFrappe: DB Schema Enumeration via Frappe-Authorization-SourceEPSS 0.4%CVE-2025-52895HIGHFrappe possibility of SQL injection due to improper validationsEPSS 0.4%CVE-2026-66003HIGHFrappe: Access control bypass via REST API dot-notation fields on linked doctypesEPSS 0.4%CVE-2026-82634HIGHFrappe Framework Development Branch Incorrect Authorization via Jinja Template Preview EndpointEPSS 0.4%CVE-2026-47185MEDIUMFrappe Has Broken Access Control in its Workspace Save APIEPSS 0.4%CVE-2025-30214HIGHFrappe vulnerable to information disclosure leading to account takeoverEPSS 0.4%CVE-2026-41581MEDIUMFrappe Vulnerable to Possible SQL Injection via get_blog_listEPSS 0.4%CVE-2024-24812MEDIUMFrappe Authenticated Reflected Cross site scripting (XSS) in portal pagesEPSS 0.4%CVE-2026-44975MEDIUMFrappe: Missing authorization on reset form toursEPSS 0.4%CVE-2026-44976MEDIUMFrappe: IDOR in update_onboarding_stepEPSS 0.4%CVE-2026-47182MEDIUMFrappe: Broken Access Control on Private FilesEPSS 0.4%CVE-2026-47422MEDIUMFrappe: Unrestricted API access to save_reportEPSS 0.4%CVE-2026-66058MEDIUMFrappe: Unrestricted access to a Document Follow APIEPSS 0.4%CVE-2025-55731MEDIUMFrappe has the possibility of Authenticated SQL Injection due to improper validationsEPSS 0.4%CVE-2025-30217MEDIUMFrappe has possibility of SQL injection due to improper validationsEPSS 0.4%CVE-2025-58375HIGHFrappe has potential SQL Injection due to missing validationEPSS 0.3%CVE-2026-66001HIGHFrappe: Improper Authorization in OAuth2 Consent EndpointEPSS 0.3%CVE-2025-66206MEDIUMFrappe vulnerable to a path traversal allowing reading certain filesEPSS 0.3%CVE-2026-3837MEDIUMFrappe Framework 16.10.0 - Stored DOM XSS in Multiple Field FormattersEPSS 0.3%CVE-2025-55732HIGHFrappe has the possibility of SQL Injection due to improper validationsEPSS 0.3%