Exposure of Frappe
Web frameworks60
exposure score
539
sites use
0
exploited
3
critical
CVEs
73 resultsCVE-2026-29077HIGHFrappe: Broken Access Control in DocShareEPSS 0.3%CVE-2025-66205HIGHFrappe has the possibility of SQL Injection due to improper validationsEPSS 0.3%CVE-2026-81731MEDIUMFrappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link DescriptionEPSS 0.3%CVE-2026-31878MEDIUMFrappe: Possible SSRF by any authenticated userEPSS 0.3%CVE-2026-3673MEDIUMFrappe Framework 16.10.0 - Stored DOM XSS in Tag Pill RendererEPSS 0.3%CVE-2026-25956MEDIUMFrappe Affected by XSS and Open Redirect in Sign UpEPSS 0.3%CVE-2026-28436LOWFrappe: Stored XSS in avatar_macro.htmlEPSS 0.3%CVE-2025-52896HIGHFrappe authenticated XSS via data importEPSS 0.3%CVE-2025-62407MEDIUMFrappe has an Open Redirect on Login PageEPSS 0.3%CVE-2026-47194HIGHFrappe: Host header poisoning can redirect magic login links to an attacker-controlled domainEPSS 0.3%CVE-2026-63654MEDIUMFrappe: Unauthenticated Workflow approval via confirm_actionEPSS 0.3%CVE-2026-31879MEDIUMFrappe Workspace modification and stored XSS due to improper resource ownership checksEPSS 0.2%CVE-2023-51769MEDIUMFrappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.EPSS 0.2%