Frappe

Frappe

88 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 08.10.2026 08:44:19
  • Zuletzt bearbeitet 08.10.2026 21:04:18

A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multiple email addresses to be accepted by manipulating the email field in the /api/method/press.api.account.signup...

  • EPSS -
  • Veröffentlicht 14.09.2026 00:00:00
  • Zuletzt bearbeitet 16.09.2026 15:17:32

Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.

  • EPSS 0.24%
  • Veröffentlicht 30.08.2026 12:34:52
  • Zuletzt bearbeitet 10.09.2026 15:53:23

Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates by supplying raw template strings. Attackers with print permission on any doc...

  • EPSS 0.17%
  • Veröffentlicht 27.08.2026 20:07:35
  • Zuletzt bearbeitet 31.08.2026 19:17:14

Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description field of the Workspace Link doctype is declared with "ignore_xss_filter": 1 in frappe/desk/doctype/workspace_link/workspace_link.j...

  • EPSS 0.31%
  • Veröffentlicht 26.08.2026 19:30:28
  • Zuletzt bearbeitet 09.09.2026 21:09:13

Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access control bypass in the REST API allows a user to read data from Linked DocTypes that they are not authorized to access. When a docu...

  • EPSS -
  • Veröffentlicht 20.08.2026 18:29:40
  • Zuletzt bearbeitet 10.09.2026 20:48:30

Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return ...

  • EPSS -
  • Veröffentlicht 20.08.2026 18:27:32
  • Zuletzt bearbeitet 16.09.2026 13:42:44

Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frappe/integrations/oauth2.py allow the OAuth2 consent flow to proceed without restricting approve to POST, without a csrf_token i...

  • EPSS -
  • Veröffentlicht 20.08.2026 18:25:01
  • Zuletzt bearbeitet 10.09.2026 20:48:30

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py checks a dictionary supplied through the fieldname parameter against forbidden standard and child-table fields before parsin...

  • EPSS -
  • Veröffentlicht 20.08.2026 18:23:52
  • Zuletzt bearbeitet 10.09.2026 20:48:30

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow approvals becaus...

  • EPSS -
  • Veröffentlicht 20.08.2026 18:15:20
  • Zuletzt bearbeitet 10.09.2026 20:48:30

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_seen endpoints in frappe/desk/like.py and frappe/desk/doctype/note/note.py do not enforce read permission before modifying _like...