Vulnerabilities in Frappe

132 results
Vexday analysis

Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.

CVE-2026-47199LOWFrappe: check_safe_sql_query Permits SELECT INTO OUTFILEEPSS 0.4%CVE-2025-30214HIGHFrappe vulnerable to information disclosure leading to account takeoverEPSS 0.4%CVE-2026-47185MEDIUMFrappe Has Broken Access Control in its Workspace Save APIEPSS 0.4%CVE-2025-52898HIGHFrappe account takeover via password reset token leakageEPSS 0.4%CVE-2024-24812MEDIUMFrappe Authenticated Reflected Cross site scripting (XSS) in portal pagesEPSS 0.4%CVE-2025-11283MEDIUMFrappe LMS Course cross site scriptingEPSS 0.4%CVE-2025-68953HIGHCertain Frappe requests are vulnerable to Path TraversalEPSS 0.4%CVE-2024-50356NONEPress has a potential 2FA bypassEPSS 0.4%CVE-2026-48127MEDIUMFrappe: Arbitrary Attachment Injection via add_attachments and upload_fileEPSS 0.4%CVE-2026-44440MEDIUMERPNext: Path Traversal Leading to Sensitive File ExposureEPSS 0.4%CVE-2025-11282MEDIUMFrappe LMS Incomplete Fix CVE-2025-55006 cross site scriptingEPSS 0.4%CVE-2025-55731MEDIUMFrappe has the possibility of Authenticated SQL Injection due to improper validationsEPSS 0.4%CVE-2026-58503MEDIUMFrappe: Unauthenticated User Enumeration via reset_passwordEPSS 0.4%CVE-2025-52895HIGHFrappe possibility of SQL injection due to improper validationsEPSS 0.4%CVE-2023-42807MEDIUMFrappe LMS SQL Injection Issue on People PageEPSS 0.3%CVE-2026-49391MEDIUMFrappe: Stored XSS in Column Headers via Data ImportEPSS 0.3%CVE-2025-11461HIGHFrappe CRM 1.53.1 — Multiple SQL Injections in Dashboard ControllerEPSS 0.3%CVE-2025-58375HIGHFrappe has potential SQL Injection due to missing validationEPSS 0.3%CVE-2025-30217MEDIUMFrappe has possibility of SQL injection due to improper validationsEPSS 0.3%CVE-2026-41482HIGHFrappe: Possible Path Traversal and Local File Inclusion via Chrome PDF GeneratorEPSS 0.3%