CVE-2025-65924
- EPSS 0.01%
- Veröffentlicht 03.02.2026 00:00:00
- Zuletzt bearbeitet 17.02.2026 17:21:04
ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are intended for plain text. Although JavaScript is blocked (preventing XSS), the HTML is still preserved in the generated PDF document. A...
CVE-2025-56379
- EPSS 0.02%
- Veröffentlicht 02.10.2025 14:15:45
- Zuletzt bearbeitet 03.10.2025 19:15:49
A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.
CVE-2018-3882
- EPSS 0.28%
- Veröffentlicht 12.09.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:13
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The searchfield parameter can be used to perform an SQL injection at...
CVE-2018-3883
- EPSS 0.28%
- Veröffentlicht 12.09.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:13
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The employee and sort_order parameter can be used to perform an SQL ...
CVE-2018-3884
- EPSS 0.28%
- Veröffentlicht 12.09.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:14
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL inject...
CVE-2018-3885
- EPSS 0.28%
- Veröffentlicht 12.09.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:14
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The order_by parameter can be used to perform an SQL injection attac...