Frappe

Frappe

61 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 01.12.2025 20:26:14
  • Zuletzt bearbeitet 04.12.2025 18:49:12

Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to lack of validation of parameters. Some information like version could be retrieved. This vulnerabili...

  • EPSS 0.24%
  • Veröffentlicht 16.10.2025 17:39:32
  • Zuletzt bearbeitet 23.10.2025 20:16:18

Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the login page, if a specific type of URL was passed in. This vulnerability is fixed in 14.98.0 and 15.83....

Exploit
  • EPSS 0.29%
  • Veröffentlicht 02.10.2025 14:15:45
  • Zuletzt bearbeitet 03.10.2025 16:18:36

ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the order_by and group_by parameters.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 02.10.2025 14:15:45
  • Zuletzt bearbeitet 03.10.2025 16:18:50

Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endpoint and a crafted script to the fieldname parameter

Exploit
  • EPSS 0.37%
  • Veröffentlicht 02.10.2025 14:15:45
  • Zuletzt bearbeitet 03.10.2025 19:15:49

A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 15.09.2025 00:00:00
  • Zuletzt bearbeitet 20.09.2025 02:57:59

In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py` is vulnerable to SQL Injection, which allows an attacker to extract information from databases by injecting a SQL query into the...

  • EPSS 0.3%
  • Veröffentlicht 20.08.2025 15:22:21
  • Zuletzt bearbeitet 22.08.2025 20:52:02

Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass o...

  • EPSS 0.33%
  • Veröffentlicht 20.08.2025 15:22:16
  • Zuletzt bearbeitet 22.08.2025 20:53:21

Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15.

  • EPSS 0.39%
  • Veröffentlicht 30.06.2025 17:19:31
  • Zuletzt bearbeitet 08.07.2025 14:43:50

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting access to a user's password reset token. This can only be exploited on self hosted instances ...

  • EPSS 0.24%
  • Veröffentlicht 30.06.2025 17:12:50
  • Zuletzt bearbeitet 08.07.2025 14:10:33

Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading to cross-site scripting (XSS). This issue has been patched in version...