Vulnerabilities in Frappe

148 results
Vexday analysis

Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.

CVE-2026-50698MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Audit Trail template renderingEPSS 0.4%CVE-2026-50710MEDIUMFrappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_configEPSS 0.4%CVE-2026-50700MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in frappe.get_avatar image renderingEPSS 0.4%CVE-2026-50704MEDIUMFrappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs renderingEPSS 0.4%CVE-2025-52898HIGHFrappe account takeover via password reset token leakageEPSS 0.4%CVE-2026-44206MEDIUMFrappe: DB Schema Enumeration via Frappe-Authorization-SourceEPSS 0.4%CVE-2026-13227HIGHERPNext v16.25.0 - Improper authorization in Prospect opportunities APIEPSS 0.4%CVE-2025-30212MEDIUMFrappe has possibility of SQL injection due to improper validationsEPSS 0.4%CVE-2026-94113HIGHFrappe ERPNext before 15.121.0 and 16.34.0 Missing Authorization in Timesheet EndpointsEPSS 0.4%CVE-2026-66003HIGHFrappe: Access control bypass via REST API dot-notation fields on linked doctypesEPSS 0.4%CVE-2025-68953HIGHCertain Frappe requests are vulnerable to Path TraversalEPSS 0.4%CVE-2026-44442CRITICALERPNext: Unauthorised Document modification due to missing validationEPSS 0.4%CVE-2026-82634HIGHFrappe Framework Development Branch Incorrect Authorization via Jinja Template Preview EndpointEPSS 0.4%CVE-2026-32954HIGHERP has a possibility SQL Injection vulnerability due to missing validationEPSS 0.4%CVE-2026-42840MEDIUMERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literalsEPSS 0.4%CVE-2025-11283MEDIUMFrappe LMS Course cross site scriptingEPSS 0.4%CVE-2026-47185MEDIUMFrappe Has Broken Access Control in its Workspace Save APIEPSS 0.4%CVE-2026-50712MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Tree View node label renderingEPSS 0.4%CVE-2026-50708MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result renderingEPSS 0.4%CVE-2026-50703MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Desktop Icon label renderingEPSS 0.4%