Vulnerabilidades en Frappe
148 resultadosAnálisis Vexday
Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.
CVE-2026-55242HIGHERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefixEPSS 0.2%CVE-2026-41317MEDIUMFrappe Press has an unsafe HTTP method / CSRF-adjacent issue on API secret generationEPSS 0.2%CVE-2023-51769MEDIUMFrappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.EPSS 0.2%CVE-2025-67730MEDIUMFrappe authenticated users can execute XSS through form description fieldsEPSS 0.2%CVE-2025-62779LOWFrappe Learning users were able to add HTML through input fields in the Job FormEPSS 0.2%CVE-2025-67734MEDIUMFrappe Authenticated Users can Execute JavaScript through its Job FormEPSS 0.2%CVE-2026-23497LOWFrappe LMS has a Stored XSS via Unsanitized Image Filename in Course and Jobs PagesEPSS 0.2%CVE-2025-64707LOWFrappe LMS revoking access did not show immediate effect as roles were cachedEPSS 0.2%