Vulnerabilities in Frappe
148 resultsVexday analysis
Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.
CVE-2026-39405CRITICALFrappe has Path Transversal via SCORMEPSS 0.5%CVE-2026-50701MEDIUMFrappe Framework 17.0.0-dev - Reflected DOM XSS in dashboard-view breadcrumb renderingEPSS 0.5%CVE-2026-44446HIGHERPNext: Possibility of SQL Injection due to missing validationEPSS 0.5%CVE-2026-47765HIGHFrappe: Lack of Permissions in restore/bulk_restoreEPSS 0.4%CVE-2026-66000LOWFrappe: Unrestricted access to Document Follow APIsEPSS 0.4%CVE-2026-29081MEDIUMFrappe: Possibility of SQL Injection due to improper fieldname sanitizationEPSS 0.4%CVE-2023-5555HIGHCross-site Scripting (XSS) - Generic in frappe/lmsEPSS 0.4%CVE-2026-42839MEDIUMERPNext 16.16.0 - Stored XSS in POS cart item renderingEPSS 0.4%CVE-2026-50026MEDIUMFrappe: Lack of permissions checks in 'relink' and 'set_email_password' endpointsEPSS 0.4%CVE-2026-44207MEDIUMFrappe: Insecure Direct Object Reference for email accountsEPSS 0.4%CVE-2026-44208MEDIUMFrappe: IDOR in `submit_discussion()`EPSS 0.4%CVE-2026-39351MEDIUMFrappe allows unrestricted Doctype access via API exploitEPSS 0.4%CVE-2026-72907MEDIUMERPNext: Broken Access Control on certain endpointEPSS 0.4%CVE-2025-59421LOWPress vulnerable to email flooding to users due to lack of validation and rate limitsEPSS 0.4%CVE-2026-27471CRITICALERP: Document access through endpoints due to missing validationEPSS 0.4%CVE-2026-44205MEDIUMFrappe: Stored Cross-Site Scripting (XSS) in User Profile through Image UploadEPSS 0.4%CVE-2026-53568MEDIUMFrappe: Stored XSS in Frappe Report/List View via 'set_link_title_field_value'EPSS 0.4%CVE-2026-47739MEDIUMFrappe: Stored XSS in NoteEPSS 0.4%CVE-2026-50705MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline renderingEPSS 0.4%CVE-2026-50704MEDIUMFrappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs renderingEPSS 0.4%