Frappe

Frappe

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 02.10.2025 14:15:45
  • Zuletzt bearbeitet 03.10.2025 16:18:50

Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endpoint and a crafted script to the fieldname parameter

Exploit
  • EPSS 0.03%
  • Veröffentlicht 15.09.2025 00:00:00
  • Zuletzt bearbeitet 20.09.2025 02:57:59

In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py` is vulnerable to SQL Injection, which allows an attacker to extract information from databases by injecting a SQL query into the...

  • EPSS 0.03%
  • Veröffentlicht 20.08.2025 15:22:21
  • Zuletzt bearbeitet 22.08.2025 20:52:02

Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass o...

  • EPSS 0.03%
  • Veröffentlicht 20.08.2025 15:22:16
  • Zuletzt bearbeitet 22.08.2025 20:53:21

Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15.

  • EPSS 0.06%
  • Veröffentlicht 30.06.2025 17:19:31
  • Zuletzt bearbeitet 08.07.2025 14:43:50

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting access to a user's password reset token. This can only be exploited on self hosted instances ...

  • EPSS 0.03%
  • Veröffentlicht 30.06.2025 17:12:50
  • Zuletzt bearbeitet 08.07.2025 14:10:33

Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading to cross-site scripting (XSS). This issue has been patched in version...

  • EPSS 0.05%
  • Veröffentlicht 30.06.2025 17:05:36
  • Zuletzt bearbeitet 08.07.2025 14:10:54

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted request, which could allow malicious person to gain access to sensitive information. This issue has been ...

  • EPSS 0.09%
  • Veröffentlicht 26.03.2025 16:18:31
  • Zuletzt bearbeitet 01.08.2025 18:04:46

Frappe is a full-stack web application framework. Prior to versions 14.93.2 and 15.55.0, a SQL Injection vulnerability has been identified in Frappe Framework which could allow a malicious actor to access sensitive information. Versions 14.93.2 and 1...

  • EPSS 0.13%
  • Veröffentlicht 25.03.2025 15:05:42
  • Zuletzt bearbeitet 01.08.2025 15:28:15

Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure that could further lead to account takeover. Versions 14.89.0 and 15.51.0 fix the issue. There's no ...

  • EPSS 0.72%
  • Veröffentlicht 25.03.2025 14:55:04
  • Zuletzt bearbeitet 01.08.2025 15:29:13

Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a specific way that could lead to remote code execution. Versions 14.9.1 and 15.52.0 contain a patch for th...