Vulnerabilities in Frappe

148 results
Vexday analysis

Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.

CVE-2023-46127MEDIUMFrappe vulnerable to HTML injection by any Desk userEPSS 37.0%CVE-2026-39352HIGHFrappe has an Arbitrary File Read via Path Traversal in render_includeEPSS 1.3%CVE-2022-23055—ERPNext - Improper user access conrolEPSS 1.2%CVE-2026-65974CRITICALERPNext: Server-Side Template Injection leading to Remote Code ExecutionEPSS 1.0%CVE-2022-23058—ERPNext - Stored XSS in My SettingsEPSS 0.9%CVE-2026-66002MEDIUMFrappe: User Enumeration via PDDREPSS 0.8%CVE-2026-72911CRITICALERPNext: Possibility of server-side template injection due to missing validationEPSS 0.7%CVE-2025-30213MEDIUMFrappe has Possibility of Remote Code Execution due to improper validationEPSS 0.7%CVE-2026-42219MEDIUMFrappe: Path Traversal via /backups RouteEPSS 0.7%CVE-2026-55852HIGHFrappe: TarSlip RCE in Package ImportEPSS 0.7%CVE-2026-54343HIGHFrappe LMS: Path Traversal in SCORM File ServingEPSS 0.7%CVE-2024-24813HIGHFrappe SQL Injection from reporting logicEPSS 0.6%CVE-2022-23057—ERPNext - Stored XSS in My ProfileEPSS 0.6%CVE-2026-48127MEDIUMFrappe: Arbitrary Attachment Injection via add_attachments and upload_fileEPSS 0.6%CVE-2026-53761HIGHFrappe CRM: Authentication Bypass via Logged Invitation Keys in crm/apiEPSS 0.6%CVE-2026-44440MEDIUMERPNext: Path Traversal Leading to Sensitive File ExposureEPSS 0.6%CVE-2026-58503MEDIUMFrappe: Unauthenticated User Enumeration via reset_passwordEPSS 0.6%CVE-2024-27105HIGHFrappe File Permissions can by bypassed using certain endpointsEPSS 0.6%CVE-2024-34074MEDIUMFrappe vuilnerable to an open redirect on login pageEPSS 0.6%CVE-2025-10655HIGHFrappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_dataEPSS 0.6%