Frappe

Frappe

61 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 11.03.2026 18:28:35
  • Zuletzt bearbeitet 13.03.2026 17:50:26

Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to. This...

  • EPSS 0.27%
  • Veröffentlicht 05.03.2026 20:23:13
  • Zuletzt bearbeitet 09.03.2026 18:44:27

Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This issu...

  • EPSS 0.19%
  • Veröffentlicht 05.03.2026 20:22:09
  • Zuletzt bearbeitet 09.03.2026 19:04:25

Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation when sharing documents, a user could share a document with a permission that they themselves didn't have. This issue has been patche...

  • EPSS 0.17%
  • Veröffentlicht 05.03.2026 20:21:35
  • Zuletzt bearbeitet 29.04.2026 01:00:01

Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted image URL that results in XSS when the avatar is displayed, and it can be triggered for other users via website page comments. Thi...

  • EPSS 0.16%
  • Veröffentlicht 10.02.2026 17:39:20
  • Zuletzt bearbeitet 17.02.2026 15:05:39

Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious signup URL for a frappe site which could lead to an open redirect (or reflected XSS, depending on the crafted payload) when a user si...

  • EPSS 0.36%
  • Veröffentlicht 05.01.2026 21:53:39
  • Zuletzt bearbeitet 09.01.2026 13:55:29

Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests that are vulnerable to path traversal attacks. Arbitrary files from the server could be retrieved due to a lack of proper sanitiz...

  • EPSS 0.42%
  • Veröffentlicht 29.12.2025 15:10:59
  • Zuletzt bearbeitet 31.12.2025 20:02:50

Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed ...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 22.12.2025 18:16:16
  • Zuletzt bearbeitet 02.01.2026 17:45:31

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

  • EPSS 0.29%
  • Veröffentlicht 03.12.2025 15:15:55
  • Zuletzt bearbeitet 05.12.2025 18:35:19

In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in sto...

  • EPSS 0.29%
  • Veröffentlicht 01.12.2025 20:29:07
  • Zuletzt bearbeitet 04.12.2025 18:41:24

Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path traversal attacks, wherein some files from the server could be retrieved if the full path was known. Sites hosted on Frappe Cloud...