CVE-2025-66206
- EPSS 0.33%
- Veröffentlicht 01.12.2025 20:29:07
- Zuletzt bearbeitet 04.12.2025 18:41:24
Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path traversal attacks, wherein some files from the server could be retrieved if the full path was known. Sites hosted on Frappe Cloud...
CVE-2025-66205
- EPSS 0.3%
- Veröffentlicht 01.12.2025 20:26:14
- Zuletzt bearbeitet 04.12.2025 18:49:12
Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to lack of validation of parameters. Some information like version could be retrieved. This vulnerabili...
CVE-2025-62407
- EPSS 0.25%
- Veröffentlicht 16.10.2025 17:39:32
- Zuletzt bearbeitet 23.10.2025 20:16:18
Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the login page, if a specific type of URL was passed in. This vulnerability is fixed in 14.98.0 and 15.83....
CVE-2025-56381
- EPSS 0.29%
- Veröffentlicht 02.10.2025 14:15:45
- Zuletzt bearbeitet 03.10.2025 16:18:36
ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the order_by and group_by parameters.
CVE-2025-56380
- EPSS 0.29%
- Veröffentlicht 02.10.2025 14:15:45
- Zuletzt bearbeitet 03.10.2025 16:18:50
Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endpoint and a crafted script to the fieldname parameter
CVE-2025-56379
- EPSS 0.38%
- Veröffentlicht 02.10.2025 14:15:45
- Zuletzt bearbeitet 03.10.2025 19:15:49
A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.
CVE-2025-52048
- EPSS 0.26%
- Veröffentlicht 15.09.2025 00:00:00
- Zuletzt bearbeitet 20.09.2025 02:57:59
In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py` is vulnerable to SQL Injection, which allows an attacker to extract information from databases by injecting a SQL query into the...
CVE-2025-58375
- EPSS 0.34%
- Veröffentlicht 06.09.2025 00:15:35
- Zuletzt bearbeitet 17.08.2026 19:16:23
Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as ver...
CVE-2025-55732
- EPSS 0.32%
- Veröffentlicht 20.08.2025 15:22:21
- Zuletzt bearbeitet 22.08.2025 20:52:02
Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass o...
CVE-2025-55731
- EPSS 0.36%
- Veröffentlicht 20.08.2025 15:22:16
- Zuletzt bearbeitet 22.08.2025 20:53:21
Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15.