Frappe

Frappe

88 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 10.07.2026 21:24:47
  • Zuletzt bearbeitet 13.07.2026 18:05:36

Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed i...

  • EPSS 0.37%
  • Veröffentlicht 10.07.2026 21:23:37
  • Zuletzt bearbeitet 14.07.2026 15:17:02

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints such as add_attachments. This issue is fixed in versions 16.20.0 and 15....

  • EPSS 0.34%
  • Veröffentlicht 10.07.2026 21:20:36
  • Zuletzt bearbeitet 13.07.2026 19:17:07

Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion were possible through secure local resource access in the Chrome PDF Generator. This issue is fixed in version 16.18.3.

  • EPSS 0.4%
  • Veröffentlicht 10.07.2026 21:14:12
  • Zuletzt bearbeitet 13.07.2026 18:05:36

Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT INTO OUTFILE queries, which could potentially work on self-hosted sites if database permissions are not well aligned and MySQL FILE...

  • EPSS 0.35%
  • Veröffentlicht 10.07.2026 21:12:28
  • Zuletzt bearbeitet 13.07.2026 19:17:31

Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.

  • EPSS 0.28%
  • Veröffentlicht 10.07.2026 21:09:58
  • Zuletzt bearbeitet 14.07.2026 15:17:01

Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2.

  • EPSS 0.31%
  • Veröffentlicht 24.06.2026 14:20:31
  • Zuletzt bearbeitet 25.06.2026 14:04:33

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger s...

  • EPSS 0.26%
  • Veröffentlicht 12.06.2026 14:45:11
  • Zuletzt bearbeitet 12.06.2026 16:17:58

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerablity in Frappe Report/List View. This issue has been patched in versions 15.107.2 and 16.17.4.

  • EPSS 0.26%
  • Veröffentlicht 12.06.2026 14:43:41
  • Zuletzt bearbeitet 12.06.2026 16:17:58

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in these endpoints allowed unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.17.0.

  • EPSS 0.28%
  • Veröffentlicht 12.06.2026 14:39:57
  • Zuletzt bearbeitet 12.06.2026 16:17:58

Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private files by guessing the file path. This issue has been patched in version 16.17.4.