CVE-2026-66000
- EPSS 0.26%
- Veröffentlicht 07.08.2026 18:25:11
- Zuletzt bearbeitet 08.09.2026 20:51:43
Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue...
CVE-2026-66058
- EPSS 0.23%
- Veröffentlicht 07.08.2026 18:17:20
- Zuletzt bearbeitet 08.09.2026 20:51:43
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixed in versions 16.20.0 and 15.112.0.
CVE-2026-66059
- EPSS 0.28%
- Veröffentlicht 07.08.2026 15:21:51
- Zuletzt bearbeitet 08.09.2026 20:51:43
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0.
CVE-2026-49391
- EPSS 0.34%
- Veröffentlicht 06.08.2026 22:17:14
- Zuletzt bearbeitet 08.09.2026 20:51:43
Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering previews and results, allowing an authenticated importer to persist script content that executes whe...
CVE-2026-47765
- EPSS 0.43%
- Veröffentlicht 06.08.2026 22:17:08
- Zuletzt bearbeitet 08.09.2026 20:51:43
Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, allowing an authenticated user to restore deleted documents without the r...
CVE-2026-47194
- EPSS 0.2%
- Veröffentlicht 06.08.2026 22:17:07
- Zuletzt bearbeitet 08.09.2026 20:51:43
Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled request Host header, allowing a remote attacker to cause emailed login links to point to an attacker...
CVE-2026-47185
- EPSS 0.39%
- Veröffentlicht 06.08.2026 22:17:07
- Zuletzt bearbeitet 08.09.2026 20:51:43
Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing workspace ownership, allowing modification of another user's private wo...
CVE-2026-12895
- EPSS 0.22%
- Veröffentlicht 29.07.2026 10:58:50
- Zuletzt bearbeitet 30.07.2026 14:12:18
SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing parameterized queries, allowing the name (docname) of ...
CVE-2026-55852
- EPSS 0.46%
- Veröffentlicht 10.07.2026 21:28:29
- Zuletzt bearbeitet 13.07.2026 18:05:36
Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tarfile members were not sufficiently checked before extraction. This issue is fixed in versions 16.23.0 and 15.112.0.
CVE-2026-42219
- EPSS 0.46%
- Veröffentlicht 10.07.2026 21:26:30
- Zuletzt bearbeitet 13.07.2026 18:05:36
Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was possible due to lack of hardening. This issue is fixed in versions 16.19.0 and 15.109.0.