Frappe

Erpnext

75 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 13.05.2026 21:14:31
  • Zuletzt bearbeitet 14.05.2026 20:10:48

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making an HTTP call to a service of the user's choice. Th...

  • EPSS 0.36%
  • Veröffentlicht 13.05.2026 21:12:52
  • Zuletzt bearbeitet 14.05.2026 20:11:20

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on an endpoint allows an authenticated adjacent attack...

  • EPSS 0.28%
  • Veröffentlicht 13.05.2026 21:11:14
  • Zuletzt bearbeitet 14.05.2026 20:04:02

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 16.9.1.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 05.05.2026 17:17:04
  • Zuletzt bearbeitet 24.07.2026 21:10:00

ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when t...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 05.05.2026 17:17:04
  • Zuletzt bearbeitet 24.07.2026 21:10:00

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.

Exploit
  • EPSS 0.61%
  • Veröffentlicht 05.05.2026 12:16:16
  • Zuletzt bearbeitet 05.05.2026 20:07:56

Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role to execute arbitrary code by exploiting frame introspection. Attackers can create a server script via...

  • EPSS 0.24%
  • Veröffentlicht 08.04.2026 00:00:00
  • Zuletzt bearbeitet 25.07.2026 10:10:00

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When generating PDFs fro...

  • EPSS 0.31%
  • Veröffentlicht 20.03.2026 04:30:26
  • Zuletzt bearbeitet 23.03.2026 19:35:20

ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-based and boolean-based blind SQL injection due to insufficient parameter validation, allowing attack...

  • EPSS 0.32%
  • Veröffentlicht 21.02.2026 06:38:11
  • Zuletzt bearbeitet 24.02.2026 14:52:50

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in ver...

  • EPSS 0.23%
  • Veröffentlicht 03.02.2026 00:00:00
  • Zuletzt bearbeitet 17.02.2026 17:21:04

ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are intended for plain text. Although JavaScript is blocked (preventing XSS), the HTML is still preserved in the generated PDF document. A...