Frappe

Frappe

88 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 12.06.2026 14:38:00
  • Zuletzt bearbeitet 12.06.2026 16:20:22

Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue has been patched in version 16.17.4.

  • EPSS 0.28%
  • Veröffentlicht 12.06.2026 14:35:55
  • Zuletzt bearbeitet 12.06.2026 16:17:58

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users in the system. This issue has been patched in versions 15.107.2 and 16.17.4.

  • EPSS 0.31%
  • Veröffentlicht 12.06.2026 14:34:00
  • Zuletzt bearbeitet 12.06.2026 16:17:58

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possible through exploiting an endpoint. This issue has been patched in versions 15.107.2 and 16.17.4.

  • EPSS 0.32%
  • Veröffentlicht 12.06.2026 14:27:58
  • Zuletzt bearbeitet 12.06.2026 16:17:58

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access other users' email configuration details. This issue has been patched in versions 15.107.0 and 16.17....

  • EPSS 0.32%
  • Veröffentlicht 12.06.2026 14:26:17
  • Zuletzt bearbeitet 12.06.2026 16:17:58

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint allows for unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.1...

  • EPSS 0.26%
  • Veröffentlicht 12.06.2026 14:23:45
  • Zuletzt bearbeitet 12.06.2026 15:56:54

Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user profile image section allows an attacker to execute malicious scripts in the browsers of other users. This issue has been patched in v...

  • EPSS 0.23%
  • Veröffentlicht 12.06.2026 14:22:46
  • Zuletzt bearbeitet 12.06.2026 15:56:54

Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Injection via get_blog_list. This issue has been patched in versions 15.106.0 and 16.16.0.

  • EPSS 0.26%
  • Veröffentlicht 12.06.2026 14:22:21
  • Zuletzt bearbeitet 12.06.2026 15:56:54

Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possible due to lack of sanitization. This issue has been patched in versions 15.106.0 and 16.16.0.

  • EPSS 1.28%
  • Veröffentlicht 20.05.2026 19:27:01
  • Zuletzt bearbeitet 23.07.2026 12:10:00

Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Path Traversal. The issue is resolved in versions 16.15.0, 15.105.0 and above.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 22.04.2026 19:52:56
  • Zuletzt bearbeitet 14.05.2026 21:24:47

An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the affected document in Desk. The vulnerable formatter implementations interpolate stored values into raw H...