CVE-2026-4894
- EPSS 0.38%
- Veröffentlicht 08.10.2026 08:44:19
- Zuletzt bearbeitet 08.10.2026 21:04:18
A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multiple email addresses to be accepted by manipulating the email field in the /api/method/press.api.account.signup...
CVE-2023-51769
- EPSS -
- Veröffentlicht 14.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 15:17:32
Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
CVE-2026-82634
- EPSS 0.24%
- Veröffentlicht 30.08.2026 12:34:52
- Zuletzt bearbeitet 10.09.2026 15:53:23
Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates by supplying raw template strings. Attackers with print permission on any doc...
CVE-2026-81731
- EPSS 0.17%
- Veröffentlicht 27.08.2026 20:07:35
- Zuletzt bearbeitet 31.08.2026 19:17:14
Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description field of the Workspace Link doctype is declared with "ignore_xss_filter": 1 in frappe/desk/doctype/workspace_link/workspace_link.j...
CVE-2026-66003
- EPSS 0.31%
- Veröffentlicht 26.08.2026 19:30:28
- Zuletzt bearbeitet 09.09.2026 21:09:13
Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access control bypass in the REST API allows a user to read data from Linked DocTypes that they are not authorized to access. When a docu...
CVE-2026-66002
- EPSS -
- Veröffentlicht 20.08.2026 18:29:40
- Zuletzt bearbeitet 10.09.2026 20:48:30
Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return ...
CVE-2026-66001
- EPSS -
- Veröffentlicht 20.08.2026 18:27:32
- Zuletzt bearbeitet 16.09.2026 13:42:44
Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frappe/integrations/oauth2.py allow the OAuth2 consent flow to proceed without restricting approve to POST, without a csrf_token i...
CVE-2026-62315
- EPSS -
- Veröffentlicht 20.08.2026 18:25:01
- Zuletzt bearbeitet 10.09.2026 20:48:30
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py checks a dictionary supplied through the fieldname parameter against forbidden standard and child-table fields before parsin...
CVE-2026-63654
- EPSS -
- Veröffentlicht 20.08.2026 18:23:52
- Zuletzt bearbeitet 10.09.2026 20:48:30
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow approvals becaus...
CVE-2026-53569
- EPSS -
- Veröffentlicht 20.08.2026 18:15:20
- Zuletzt bearbeitet 10.09.2026 20:48:30
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_seen endpoints in frappe/desk/like.py and frappe/desk/doctype/note/note.py do not enforce read permission before modifying _like...