Frappe

Frappe

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 10.02.2026 17:39:20
  • Zuletzt bearbeitet 17.02.2026 15:05:39

Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious signup URL for a frappe site which could lead to an open redirect (or reflected XSS, depending on the crafted payload) when a user si...

  • EPSS 0.07%
  • Veröffentlicht 05.01.2026 21:53:39
  • Zuletzt bearbeitet 09.01.2026 13:55:29

Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests that are vulnerable to path traversal attacks. Arbitrary files from the server could be retrieved due to a lack of proper sanitiz...

  • EPSS 0.15%
  • Veröffentlicht 29.12.2025 15:10:59
  • Zuletzt bearbeitet 31.12.2025 20:02:50

Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed ...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 22.12.2025 18:16:16
  • Zuletzt bearbeitet 02.01.2026 17:45:31

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

  • EPSS 0.07%
  • Veröffentlicht 03.12.2025 15:15:55
  • Zuletzt bearbeitet 05.12.2025 18:35:19

In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in sto...

  • EPSS 0.07%
  • Veröffentlicht 01.12.2025 20:29:07
  • Zuletzt bearbeitet 04.12.2025 18:41:24

Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path traversal attacks, wherein some files from the server could be retrieved if the full path was known. Sites hosted on Frappe Cloud...

  • EPSS 0.04%
  • Veröffentlicht 01.12.2025 20:26:14
  • Zuletzt bearbeitet 04.12.2025 18:49:12

Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to lack of validation of parameters. Some information like version could be retrieved. This vulnerabili...

  • EPSS 0.05%
  • Veröffentlicht 16.10.2025 17:39:32
  • Zuletzt bearbeitet 23.10.2025 20:16:18

Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the login page, if a specific type of URL was passed in. This vulnerability is fixed in 14.98.0 and 15.83....

Exploit
  • EPSS 0.03%
  • Veröffentlicht 02.10.2025 14:15:45
  • Zuletzt bearbeitet 03.10.2025 16:18:36

ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the order_by and group_by parameters.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 02.10.2025 14:15:45
  • Zuletzt bearbeitet 03.10.2025 19:15:49

A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.