Frappe

Frappe

61 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 30.06.2025 17:05:36
  • Zuletzt bearbeitet 08.07.2025 14:10:54

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted request, which could allow malicious person to gain access to sensitive information. This issue has been ...

  • EPSS 0.32%
  • Veröffentlicht 26.03.2025 16:18:31
  • Zuletzt bearbeitet 01.08.2025 18:04:46

Frappe is a full-stack web application framework. Prior to versions 14.93.2 and 15.55.0, a SQL Injection vulnerability has been identified in Frappe Framework which could allow a malicious actor to access sensitive information. Versions 14.93.2 and 1...

  • EPSS 0.38%
  • Veröffentlicht 25.03.2025 15:05:42
  • Zuletzt bearbeitet 01.08.2025 15:28:15

Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure that could further lead to account takeover. Versions 14.89.0 and 15.51.0 fix the issue. There's no ...

  • EPSS 0.64%
  • Veröffentlicht 25.03.2025 14:55:04
  • Zuletzt bearbeitet 01.08.2025 15:29:13

Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a specific way that could lead to remote code execution. Versions 14.9.1 and 15.52.0 contain a patch for th...

  • EPSS 0.41%
  • Veröffentlicht 25.03.2025 14:21:32
  • Zuletzt bearbeitet 01.08.2025 15:52:46

Frappe is a full-stack web application framework. An SQL Injection vulnerability has been identified in Frappe Framework prior to versions 14.89.0 and 15.51.0 which could allow a malicious actor to access sensitive information. Versions 14.89.0 and 1...

  • EPSS 0.57%
  • Veröffentlicht 14.05.2024 15:38:27
  • Zuletzt bearbeitet 04.08.2025 14:37:59

Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerabili...

  • EPSS 0.59%
  • Veröffentlicht 21.03.2024 02:52:18
  • Zuletzt bearbeitet 31.07.2025 20:23:40

Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed using certain endpoints, granting less privileged users permission to delete or clone a file. Versions 14.66.3 and 15.16.0 contai...

  • EPSS 0.65%
  • Veröffentlicht 21.03.2024 02:52:11
  • Zuletzt bearbeitet 31.07.2025 20:16:59

Frappe is a full-stack web application framework. Prior to versions 14.64.0 and 15.0.0, SQL injection from a particular whitelisted method can result in access to data which the user doesn't have permission to access. Versions 14.64.0 and 15.0.0 cont...

  • EPSS 0.38%
  • Veröffentlicht 07.02.2024 15:15:08
  • Zuletzt bearbeitet 21.11.2024 08:59:45

Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and a tightly integrated client side library. Prior to versions 14.59.0 and 15.5.0, portal pages are susceptible to Cross-Site Scripting (XSS) which can ...

  • EPSS 36.98%
  • Veröffentlicht 23.10.2023 15:15:09
  • Zuletzt bearbeitet 21.11.2024 08:27:56

Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. ...