Frappe

Erpnext

61 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 03.06.2026 17:44:41
  • Zuletzt bearbeitet 04.06.2026 15:23:52

An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, description, or image fields of an Item and trigger unescaped rendering in the Point of Sale (POS) cart interface for every operat...

  • EPSS 0.24%
  • Veröffentlicht 03.06.2026 17:35:04
  • Zuletzt bearbeitet 04.06.2026 15:23:52

An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of Sale (POS) interface for every operator who selects that customer. This issue affects...

  • EPSS 0.15%
  • Veröffentlicht 13.05.2026 21:20:20
  • Zuletzt bearbeitet 15.05.2026 16:20:17

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixe...

  • EPSS 0.31%
  • Veröffentlicht 13.05.2026 21:19:07
  • Zuletzt bearbeitet 14.05.2026 19:41:12

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulne...

  • EPSS 0.27%
  • Veröffentlicht 13.05.2026 21:18:17
  • Zuletzt bearbeitet 14.05.2026 20:01:40

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive informati...

  • EPSS 0.22%
  • Veröffentlicht 13.05.2026 21:17:06
  • Zuletzt bearbeitet 14.05.2026 20:02:51

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enables an authenticated attacker to read files from th...

  • EPSS 0.16%
  • Veröffentlicht 13.05.2026 21:14:31
  • Zuletzt bearbeitet 14.05.2026 20:10:48

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making an HTTP call to a service of the user's choice. Th...

  • EPSS 0.36%
  • Veröffentlicht 13.05.2026 21:12:52
  • Zuletzt bearbeitet 14.05.2026 20:11:20

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on an endpoint allows an authenticated adjacent attack...

  • EPSS 0.28%
  • Veröffentlicht 13.05.2026 21:11:14
  • Zuletzt bearbeitet 14.05.2026 20:04:02

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 16.9.1.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 05.05.2026 17:17:04
  • Zuletzt bearbeitet 08.05.2026 17:05:35

ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when t...