Frappe

Erpnext

75 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 08.10.2026 08:44:19
  • Zuletzt bearbeitet 08.10.2026 21:04:18

A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multiple email addresses to be accepted by manipulating the email field in the /api/method/press.api.account.signup...

  • EPSS 0.22%
  • Veröffentlicht 23.09.2026 15:35:09
  • Zuletzt bearbeitet 29.09.2026 02:16:56

Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply arbitrary dotted Python paths to invoke...

  • EPSS 0.24%
  • Veröffentlicht 20.09.2026 11:56:08
  • Zuletzt bearbeitet 21.09.2026 17:19:19

Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_da...

  • EPSS 0.26%
  • Veröffentlicht 17.08.2026 20:45:45
  • Zuletzt bearbeitet 09.09.2026 21:11:46

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates it into raw SQL in get_sales_de...

  • EPSS 0.56%
  • Veröffentlicht 17.08.2026 20:44:20
  • Zuletzt bearbeitet 09.09.2026 21:11:46

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restric...

  • EPSS 0.38%
  • Veröffentlicht 10.08.2026 21:17:25
  • Zuletzt bearbeitet 09.09.2026 20:55:04

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render subj...

  • EPSS 0.28%
  • Veröffentlicht 10.08.2026 21:17:25
  • Zuletzt bearbeitet 09.09.2026 20:55:04

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions across erpnext/accounts/doctype/accou...

  • EPSS 0.27%
  • Veröffentlicht 10.08.2026 21:17:25
  • Zuletzt bearbeitet 09.09.2026 20:55:04

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not apply Customer and ...

  • EPSS 0.29%
  • Veröffentlicht 10.08.2026 20:51:23
  • Zuletzt bearbeitet 08.09.2026 20:54:37

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WHERE clause from request-influenced posting_date and...

  • EPSS 0.25%
  • Veröffentlicht 10.08.2026 20:49:26
  • Zuletzt bearbeitet 08.09.2026 20:54:37

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without enforcing Account create permission, allowing an auth...