CVE-2026-66002
- EPSS -
- Veröffentlicht 20.08.2026 18:29:40
- Zuletzt bearbeitet 20.08.2026 19:16:58
Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return ...
CVE-2026-66001
- EPSS -
- Veröffentlicht 20.08.2026 18:27:32
- Zuletzt bearbeitet 20.08.2026 19:16:58
Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frappe/integrations/oauth2.py allow the OAuth2 consent flow to proceed without restricting approve to POST, without a csrf_token i...
CVE-2026-62315
- EPSS -
- Veröffentlicht 20.08.2026 18:25:01
- Zuletzt bearbeitet 20.08.2026 19:16:56
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py checks a dictionary supplied through the fieldname parameter against forbidden standard and child-table fields before parsin...
CVE-2026-63654
- EPSS -
- Veröffentlicht 20.08.2026 18:23:52
- Zuletzt bearbeitet 20.08.2026 20:17:45
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow approvals becaus...
CVE-2026-53569
- EPSS -
- Veröffentlicht 20.08.2026 18:15:20
- Zuletzt bearbeitet 20.08.2026 19:16:54
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_seen endpoints in frappe/desk/like.py and frappe/desk/doctype/note/note.py do not enforce read permission before modifying _like...
CVE-2026-66000
- EPSS 0.26%
- Veröffentlicht 07.08.2026 18:25:11
- Zuletzt bearbeitet 07.08.2026 19:18:51
Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue...
CVE-2026-66058
- EPSS 0.23%
- Veröffentlicht 07.08.2026 18:17:20
- Zuletzt bearbeitet 10.08.2026 13:19:52
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixed in versions 16.20.0 and 15.112.0.
CVE-2026-66059
- EPSS 0.28%
- Veröffentlicht 07.08.2026 15:21:51
- Zuletzt bearbeitet 08.08.2026 04:17:50
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0.
CVE-2026-49391
- EPSS 0.34%
- Veröffentlicht 06.08.2026 22:17:14
- Zuletzt bearbeitet 07.08.2026 18:17:18
Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering previews and results, allowing an authenticated importer to persist script content that executes whe...
CVE-2026-47765
- EPSS 0.43%
- Veröffentlicht 06.08.2026 22:17:08
- Zuletzt bearbeitet 07.08.2026 16:17:24
Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, allowing an authenticated user to restore deleted documents without the r...