Vulnerabilidades em Frappe

148 resultados
Análise Vexday

Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.

CVE-2025-62158LOWFrappe had attachments made by students to their assignments of type Text set to publicEPSS 0.3%CVE-2026-39415MEDIUMFrappe Learning Management System has Client-Side Manipulation of Quiz ScoresEPSS 0.3%CVE-2026-25956MEDIUMFrappe Affected by XSS and Open Redirect in Sign UpEPSS 0.3%CVE-2026-28436LOWFrappe: Stored XSS in avatar_macro.htmlEPSS 0.3%CVE-2025-52896HIGHFrappe authenticated XSS via data importEPSS 0.3%CVE-2026-44441MEDIUMERPNext: Possible SSRF by any authenticated userEPSS 0.3%CVE-2026-41430LOWPress vulnerable to reflected XSS on login redirectionEPSS 0.3%CVE-2025-62407MEDIUMFrappe has an Open Redirect on Login PageEPSS 0.3%CVE-2025-55006MEDIUMFrappe Learning Holds Potential for Malicious SVG Upload in Image Upload FeatureEPSS 0.3%CVE-2026-47194HIGHFrappe: Host header poisoning can redirect magic login links to an attacker-controlled domainEPSS 0.3%CVE-2026-63654MEDIUMFrappe: Unauthenticated Workflow approval via confirm_actionEPSS 0.3%CVE-2026-44448MEDIUMERPNext: Unauthorised Document modification due to missing validationEPSS 0.3%CVE-2025-59415MEDIUMFrappe Learning vulnerable to Malicious Content upload via Profile bio fieldEPSS 0.2%CVE-2026-46546LOWFrappe LMS: HTML injection in user-controlled metadataEPSS 0.2%CVE-2026-31879MEDIUMFrappe Workspace modification and stored XSS due to improper resource ownership checksEPSS 0.2%CVE-2026-96672MEDIUMFrappe ERPNext before 16.34.1 Unauthorized Method InvocationEPSS 0.2%CVE-2025-64705LOWFrappe user was able to access the submission of other studentsEPSS 0.2%CVE-2025-66581LOWFrappe LMS is Missing Server-Side Authorization in Business LogicEPSS 0.2%CVE-2025-68928MEDIUMFrappe CRM vulnerable to authenticated XSS via website fieldEPSS 0.2%CVE-2025-62778LOWFrappe Learning allowed students to access the Quiz Form via direct URLEPSS 0.2%