← back
CVE-2025-28062highCWE-352

CVE-2025-28062

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 8.1epss 0.8%
from disclosure to weapon0 days
Published on NVDMay 5
1st PoCApr 29
exploitation probability
0.8%top 47% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.