Vulnerabilidades em Frappe
148 resultadosAnálise Vexday
Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.
CVE-2025-11281LOWFrappe LMS Unpublished Course courses access controlEPSS 0.4%CVE-2025-30217MEDIUMFrappe has possibility of SQL injection due to improper validationsEPSS 0.4%CVE-2026-72906MEDIUMERPNext: Unauthorised triggering of automated emails due to missing validationEPSS 0.4%CVE-2025-11461HIGHFrappe CRM 1.53.1 — Multiple SQL Injections in Dashboard ControllerEPSS 0.3%CVE-2025-58375HIGHFrappe has potential SQL Injection due to missing validationEPSS 0.3%CVE-2026-66001HIGHFrappe: Improper Authorization in OAuth2 Consent EndpointEPSS 0.3%CVE-2025-66206MEDIUMFrappe vulnerable to a path traversal allowing reading certain filesEPSS 0.3%CVE-2026-45081MEDIUMFrappe HR: Permission Bypass in HRMS Leave Details APIEPSS 0.3%CVE-2026-3837MEDIUMFrappe Framework 16.10.0 - Stored DOM XSS in Multiple Field FormattersEPSS 0.3%CVE-2026-34606MEDIUMStored XSS in Frappe LMSEPSS 0.3%CVE-2025-55732HIGHFrappe has the possibility of SQL Injection due to improper validationsEPSS 0.3%CVE-2026-26977MEDIUMFrappe Learning Management System exposes details of unpublished courses to unauthorized usersEPSS 0.3%CVE-2025-58439HIGHERP: Possibility of SQL injection due to missing validationEPSS 0.3%CVE-2025-66205HIGHFrappe has the possibility of SQL Injection due to improper validationsEPSS 0.3%CVE-2026-81731MEDIUMFrappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link DescriptionEPSS 0.3%CVE-2026-29077HIGHFrappe: Broken Access Control in DocShareEPSS 0.3%CVE-2025-53545MEDIUMPress has a potential 2FA bypassEPSS 0.3%CVE-2026-26031LOWFrappe LMS affected by unauthorised user was able to access the full list of batch enrolled studentsEPSS 0.3%CVE-2026-3673MEDIUMFrappe Framework 16.10.0 - Stored DOM XSS in Tag Pill RendererEPSS 0.3%CVE-2026-31878MEDIUMFrappe: Possible SSRF by any authenticated userEPSS 0.3%