CVE-2025-65923
- EPSS 0.16%
- Veröffentlicht 03.02.2026 00:00:00
- Zuletzt bearbeitet 11.02.2026 16:50:44
A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1 when using the Update Existing Recordsoption. An attacker can embed malicious JavaScript code into a CSV field, which is then sto...
CVE-2025-67289
- EPSS 0.45%
- Veröffentlicht 22.12.2025 18:16:16
- Zuletzt bearbeitet 05.07.2026 17:17:26
An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
CVE-2025-66435
- EPSS 0.33%
- Veröffentlicht 15.12.2025 00:00:00
- Zuletzt bearbeitet 23.12.2025 17:56:56
An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (contract_terms) using frappe.render_template() with a user...
CVE-2025-66438
- EPSS 0.49%
- Veröffentlicht 15.12.2025 00:00:00
- Zuletzt bearbeitet 05.01.2026 18:20:23
A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, the API frappe.www.printview.get_html_and_style() triggers the rendering of the html field inside a Pri...
CVE-2025-66440
- EPSS 0.37%
- Veröffentlicht 15.12.2025 00:00:00
- Zuletzt bearbeitet 05.01.2026 18:23:39
An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/accounts/doctype/payment_entry/payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from ...
CVE-2025-66439
- EPSS 0.37%
- Veröffentlicht 15.12.2025 00:00:00
- Zuletzt bearbeitet 05.01.2026 18:21:38
An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.accounts.doctype.payment_entry.payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from ...
CVE-2025-66437
- EPSS 0.59%
- Veröffentlicht 15.12.2025 00:00:00
- Zuletzt bearbeitet 05.01.2026 18:19:07
An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders address templates using frappe.render_template() with a context derived from the address_dict par...
CVE-2025-66436
- EPSS 0.33%
- Veröffentlicht 15.12.2025 00:00:00
- Zuletzt bearbeitet 23.12.2025 17:54:23
An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (terms) using frappe.render_template() with a user-suppl...
CVE-2025-66434
- EPSS 0.58%
- Veröffentlicht 15.12.2025 00:00:00
- Zuletzt bearbeitet 23.12.2025 17:57:35
An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (body_text) using frappe.render_template() with a user-su...
- EPSS 0.34%
- Veröffentlicht 03.12.2025 15:15:55
- Zuletzt bearbeitet 05.12.2025 18:35:19
In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in sto...