Vulnerabilidades em Frappe
148 resultadosAnálise Vexday
Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.
CVE-2026-50709MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Notifications Events color renderingEPSS 0.4%CVE-2026-40888MEDIUMFrappe HR vulnerable to Improper Access ControlEPSS 0.4%CVE-2026-40889MEDIUMFrappe HR has Improper Access Control on FilesEPSS 0.4%CVE-2025-30214HIGHFrappe vulnerable to information disclosure leading to account takeoverEPSS 0.4%CVE-2023-42807MEDIUMFrappe LMS SQL Injection Issue on People PageEPSS 0.4%CVE-2025-11282MEDIUMFrappe LMS Incomplete Fix CVE-2025-55006 cross site scriptingEPSS 0.4%CVE-2025-52895HIGHFrappe possibility of SQL injection due to improper validationsEPSS 0.4%CVE-2026-41581MEDIUMFrappe Vulnerable to Possible SQL Injection via get_blog_listEPSS 0.4%CVE-2024-24812MEDIUMFrappe Authenticated Reflected Cross site scripting (XSS) in portal pagesEPSS 0.4%CVE-2026-47182MEDIUMFrappe: Broken Access Control on Private FilesEPSS 0.4%CVE-2026-44445MEDIUMERPNext: XML External Entity (XEE) Reference Vulnerability in the EDI ModuleEPSS 0.4%CVE-2026-66058MEDIUMFrappe: Unrestricted access to a Document Follow APIEPSS 0.4%CVE-2026-44976MEDIUMFrappe: IDOR in update_onboarding_stepEPSS 0.4%CVE-2026-47422MEDIUMFrappe: Unrestricted API access to save_reportEPSS 0.4%CVE-2026-44975MEDIUMFrappe: Missing authorization on reset form toursEPSS 0.4%CVE-2026-41320MEDIUMFrappe HR has possibility of SQL Injection due to improper field sanitizationEPSS 0.4%CVE-2026-39385HIGHFrappe LMS enrollment bypass in paid courses via unrelated batchEPSS 0.4%CVE-2024-50356NONEPress has a potential 2FA bypassEPSS 0.4%CVE-2025-55731MEDIUMFrappe has the possibility of Authenticated SQL Injection due to improper validationsEPSS 0.4%CVE-2026-12895HIGHSQL Injection in Frappe's ERPNextEPSS 0.4%