CVE-2026-65822
- EPSS 0.26%
- Veröffentlicht 17.08.2026 20:45:45
- Zuletzt bearbeitet 18.08.2026 13:17:27
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates it into raw SQL in get_sales_de...
CVE-2026-65974
- EPSS 0.56%
- Veröffentlicht 17.08.2026 20:44:20
- Zuletzt bearbeitet 18.08.2026 15:16:56
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restric...
CVE-2026-72911
- EPSS 0.38%
- Veröffentlicht 10.08.2026 21:17:25
- Zuletzt bearbeitet 13.08.2026 16:19:02
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render subj...
CVE-2026-72910
- EPSS 0.28%
- Veröffentlicht 10.08.2026 21:17:25
- Zuletzt bearbeitet 11.08.2026 18:18:25
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions across erpnext/accounts/doctype/accou...
CVE-2026-72909
- EPSS 0.27%
- Veröffentlicht 10.08.2026 21:17:25
- Zuletzt bearbeitet 11.08.2026 14:17:15
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not apply Customer and ...
CVE-2026-72908
- EPSS 0.29%
- Veröffentlicht 10.08.2026 20:51:23
- Zuletzt bearbeitet 12.08.2026 23:17:22
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WHERE clause from request-influenced posting_date and...
CVE-2026-72907
- EPSS 0.25%
- Veröffentlicht 10.08.2026 20:49:26
- Zuletzt bearbeitet 13.08.2026 16:19:02
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without enforcing Account create permission, allowing an auth...
CVE-2026-72906
- EPSS 0.2%
- Veröffentlicht 10.08.2026 20:47:39
- Zuletzt bearbeitet 11.08.2026 18:18:25
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py lacks a Process Statement Of A...
CVE-2026-13227
- EPSS 0.25%
- Veröffentlicht 04.08.2026 20:53:53
- Zuletzt bearbeitet 05.08.2026 16:16:49
An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects ERPNext: before 1...
CVE-2026-12895
- EPSS 0.22%
- Veröffentlicht 29.07.2026 10:58:50
- Zuletzt bearbeitet 30.07.2026 14:12:18
SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing parameterized queries, allowing the name (docname) of ...