CVE-2026-72906
- EPSS 0.2%
- Veröffentlicht 10.08.2026 20:47:39
- Zuletzt bearbeitet 08.09.2026 20:54:37
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py lacks a Process Statement Of A...
CVE-2026-13227
- EPSS 0.25%
- Veröffentlicht 04.08.2026 20:53:53
- Zuletzt bearbeitet 28.08.2026 15:31:31
An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects ERPNext: before 1...
CVE-2026-12895
- EPSS 0.22%
- Veröffentlicht 29.07.2026 10:58:50
- Zuletzt bearbeitet 30.07.2026 14:12:18
SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing parameterized queries, allowing the name (docname) of ...
CVE-2026-55242
- EPSS 0.14%
- Veröffentlicht 15.07.2026 15:38:31
- Zuletzt bearbeitet 15.07.2026 20:49:41
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthor...
CVE-2026-42839
- EPSS 0.26%
- Veröffentlicht 03.06.2026 17:44:41
- Zuletzt bearbeitet 22.07.2026 20:10:00
An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, description, or image fields of an Item and trigger unescaped rendering in the Point of Sale (POS) cart interface for every operat...
CVE-2026-42840
- EPSS 0.24%
- Veröffentlicht 03.06.2026 17:35:04
- Zuletzt bearbeitet 22.07.2026 20:10:00
An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of Sale (POS) interface for every operator who selects that customer. This issue affects...
CVE-2026-44448
- EPSS 0.15%
- Veröffentlicht 13.05.2026 21:20:20
- Zuletzt bearbeitet 15.05.2026 16:20:17
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixe...
CVE-2026-44447
- EPSS 0.31%
- Veröffentlicht 13.05.2026 21:19:07
- Zuletzt bearbeitet 14.05.2026 19:41:12
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulne...
CVE-2026-44446
- EPSS 0.27%
- Veröffentlicht 13.05.2026 21:18:17
- Zuletzt bearbeitet 14.05.2026 20:01:40
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive informati...
CVE-2026-44445
- EPSS 0.22%
- Veröffentlicht 13.05.2026 21:17:06
- Zuletzt bearbeitet 14.05.2026 20:02:51
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enables an authenticated attacker to read files from th...