CVE-2026-38432
- EPSS 0.18%
- Veröffentlicht 05.05.2026 17:17:04
- Zuletzt bearbeitet 24.07.2026 21:10:00
ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when t...
CVE-2026-38431
- EPSS 0.39%
- Veröffentlicht 05.05.2026 17:17:04
- Zuletzt bearbeitet 24.07.2026 21:10:00
ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.
CVE-2023-54345
- EPSS 0.61%
- Veröffentlicht 05.05.2026 12:16:16
- Zuletzt bearbeitet 05.05.2026 20:07:56
Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role to execute arbitrary code by exploiting frame introspection. Attackers can create a server script via...
CVE-2026-31017
- EPSS 0.24%
- Veröffentlicht 08.04.2026 00:00:00
- Zuletzt bearbeitet 25.07.2026 10:10:00
A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When generating PDFs fro...
CVE-2026-32954
- EPSS 0.31%
- Veröffentlicht 20.03.2026 04:30:26
- Zuletzt bearbeitet 23.03.2026 19:35:20
ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-based and boolean-based blind SQL injection due to insufficient parameter validation, allowing attack...
CVE-2026-27471
- EPSS 0.32%
- Veröffentlicht 21.02.2026 06:38:11
- Zuletzt bearbeitet 24.02.2026 14:52:50
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in ver...
CVE-2025-65924
- EPSS 0.23%
- Veröffentlicht 03.02.2026 00:00:00
- Zuletzt bearbeitet 17.02.2026 17:21:04
ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are intended for plain text. Although JavaScript is blocked (preventing XSS), the HTML is still preserved in the generated PDF document. A...
CVE-2025-65923
- EPSS 0.16%
- Veröffentlicht 03.02.2026 00:00:00
- Zuletzt bearbeitet 11.02.2026 16:50:44
A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1 when using the Update Existing Recordsoption. An attacker can embed malicious JavaScript code into a CSV field, which is then sto...
CVE-2025-67289
- EPSS 0.45%
- Veröffentlicht 22.12.2025 18:16:16
- Zuletzt bearbeitet 05.07.2026 17:17:26
An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
CVE-2025-66434
- EPSS 0.58%
- Veröffentlicht 15.12.2025 00:00:00
- Zuletzt bearbeitet 23.12.2025 17:57:35
An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (body_text) using frappe.render_template() with a user-su...