CVE-2025-30212
- EPSS 0.1%
- Veröffentlicht 25.03.2025 14:21:32
- Zuletzt bearbeitet 01.08.2025 15:52:46
Frappe is a full-stack web application framework. An SQL Injection vulnerability has been identified in Frappe Framework prior to versions 14.89.0 and 15.51.0 which could allow a malicious actor to access sensitive information. Versions 14.89.0 and 1...
CVE-2024-34074
- EPSS 0.27%
- Veröffentlicht 14.05.2024 15:38:27
- Zuletzt bearbeitet 04.08.2025 14:37:59
Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerabili...
CVE-2024-27105
- EPSS 0.06%
- Veröffentlicht 21.03.2024 02:52:18
- Zuletzt bearbeitet 31.07.2025 20:23:40
Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed using certain endpoints, granting less privileged users permission to delete or clone a file. Versions 14.66.3 and 15.16.0 contai...
CVE-2024-24813
- EPSS 0.39%
- Veröffentlicht 21.03.2024 02:52:11
- Zuletzt bearbeitet 31.07.2025 20:16:59
Frappe is a full-stack web application framework. Prior to versions 14.64.0 and 15.0.0, SQL injection from a particular whitelisted method can result in access to data which the user doesn't have permission to access. Versions 14.64.0 and 15.0.0 cont...
CVE-2024-24812
- EPSS 0.45%
- Veröffentlicht 07.02.2024 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:59:45
Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and a tightly integrated client side library. Prior to versions 14.59.0 and 15.5.0, portal pages are susceptible to Cross-Site Scripting (XSS) which can ...
CVE-2023-46127
- EPSS 23.9%
- Veröffentlicht 23.10.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:27:56
Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. ...
CVE-2023-41328
- EPSS 0.2%
- Veröffentlicht 06.09.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 08:21:05
Frappe is a low code web framework written in Python and Javascript. A SQL Injection vulnerability has been identified in the Frappe Framework which could allow a malicious actor to access sensitive information. This issue has been addressed in versi...
CVE-2022-41712
- EPSS 0.36%
- Veröffentlicht 25.11.2022 18:15:11
- Zuletzt bearbeitet 29.04.2025 15:15:49
Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correctly validate the information injected by the user in the import_file parameter.
CVE-2022-3988
- EPSS 0.3%
- Veröffentlicht 14.11.2022 11:15:10
- Zuletzt bearbeitet 21.11.2024 07:20:41
A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functionality of the file frappe/templates/includes/navbar/navbar_search.html of the component Search. The manipulation of the argument q le...
CVE-2020-35175
- EPSS 0.24%
- Veröffentlicht 11.12.2020 23:15:14
- Zuletzt bearbeitet 21.11.2024 05:26:54
Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.