CVE-2025-66205
- EPSS 0.26%
- Veröffentlicht 01.12.2025 20:26:14
- Zuletzt bearbeitet 04.12.2025 18:49:12
Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to lack of validation of parameters. Some information like version could be retrieved. This vulnerabili...
CVE-2025-62407
- EPSS 0.24%
- Veröffentlicht 16.10.2025 17:39:32
- Zuletzt bearbeitet 23.10.2025 20:16:18
Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the login page, if a specific type of URL was passed in. This vulnerability is fixed in 14.98.0 and 15.83....
CVE-2025-56381
- EPSS 0.29%
- Veröffentlicht 02.10.2025 14:15:45
- Zuletzt bearbeitet 03.10.2025 16:18:36
ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the order_by and group_by parameters.
CVE-2025-56380
- EPSS 0.29%
- Veröffentlicht 02.10.2025 14:15:45
- Zuletzt bearbeitet 03.10.2025 16:18:50
Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endpoint and a crafted script to the fieldname parameter
CVE-2025-56379
- EPSS 0.37%
- Veröffentlicht 02.10.2025 14:15:45
- Zuletzt bearbeitet 03.10.2025 19:15:49
A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.
CVE-2025-52048
- EPSS 0.24%
- Veröffentlicht 15.09.2025 00:00:00
- Zuletzt bearbeitet 20.09.2025 02:57:59
In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py` is vulnerable to SQL Injection, which allows an attacker to extract information from databases by injecting a SQL query into the...
CVE-2025-55732
- EPSS 0.3%
- Veröffentlicht 20.08.2025 15:22:21
- Zuletzt bearbeitet 22.08.2025 20:52:02
Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass o...
CVE-2025-55731
- EPSS 0.33%
- Veröffentlicht 20.08.2025 15:22:16
- Zuletzt bearbeitet 22.08.2025 20:53:21
Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15.
CVE-2025-52898
- EPSS 0.39%
- Veröffentlicht 30.06.2025 17:19:31
- Zuletzt bearbeitet 08.07.2025 14:43:50
Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting access to a user's password reset token. This can only be exploited on self hosted instances ...
CVE-2025-52896
- EPSS 0.24%
- Veröffentlicht 30.06.2025 17:12:50
- Zuletzt bearbeitet 08.07.2025 14:10:33
Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading to cross-site scripting (XSS). This issue has been patched in version...