Vulnerabilidades en Frappe

148 resultados
Análisis Vexday

Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.

CVE-2026-47199LOWFrappe: check_safe_sql_query Permits SELECT INTO OUTFILEEPSS 0.5%CVE-2026-49394HIGHFrappe: Auth. bypass via update_pageEPSS 0.5%CVE-2026-50699MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule renderingEPSS 0.5%CVE-2026-44447HIGHERPNext: Possibility of SQL Injection due to missing validationEPSS 0.5%CVE-2026-72908MEDIUMERPNext: Possibility of SQL injection due to missing validationEPSS 0.5%CVE-2025-68929CRITICALFrappe may be vulnerable remote code execution due to server-side template injectionEPSS 0.5%CVE-2026-41482HIGHFrappe: Possible Path Traversal and Local File Inclusion via Chrome PDF GeneratorEPSS 0.5%CVE-2024-49751LOWFrappe Press possible HTML injection through SaaS Signup inputsEPSS 0.5%CVE-2026-72910HIGHERPNext: Unauthorised modification of master data due to missing validationEPSS 0.5%CVE-2023-41328MEDIUMPossibility limited SQL injection due to insufficient validation in FrappeEPSS 0.5%CVE-2026-62315HIGHFrappe: Mass assignment via set_valueEPSS 0.5%CVE-2025-11280MEDIUMFrappe LMS Assignment Picture files direct requestEPSS 0.5%CVE-2026-54524HIGHFrappe HR: SQL Injection in HRMS Salary Payments Based on Payment Mode ReportEPSS 0.5%CVE-2026-66059MEDIUMFrappe: Field-level permission bypass via Document FollowEPSS 0.5%CVE-2026-72909HIGHERPNext: Broken Access Control on certain endpointsEPSS 0.5%CVE-2026-35614CRITICALFrappe has a SQL injection in bulk_updateEPSS 0.5%CVE-2026-31877CRITICALFrappe SQL Injection due to improper field sanitizationEPSS 0.5%CVE-2026-49391MEDIUMFrappe: Stored XSS in Column Headers via Data ImportEPSS 0.5%CVE-2026-53569MEDIUMFrappe: Missing authorization in toggle_like and mark_as_seenEPSS 0.5%CVE-2026-65822HIGHERPNext: SQL Injection in "Inactive Customers" report via unvalidated `doctype` filterEPSS 0.5%