Vulnerabilities in Frappe
132 resultsVexday analysis
Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.
CVE-2025-66206MEDIUMFrappe vulnerable to a path traversal allowing reading certain filesEPSS 0.3%CVE-2025-11281LOWFrappe LMS Unpublished Course courses access controlEPSS 0.3%CVE-2026-27471CRITICALERP: Document access through endpoints due to missing validationEPSS 0.3%CVE-2026-44208MEDIUMFrappe: IDOR in `submit_discussion()`EPSS 0.3%CVE-2026-44207MEDIUMFrappe: Insecure Direct Object Reference for email accountsEPSS 0.3%CVE-2025-55732HIGHFrappe has the possibility of SQL Injection due to improper validationsEPSS 0.3%CVE-2026-32954HIGHERP has a possibility SQL Injection vulnerability due to missing validationEPSS 0.3%CVE-2026-50699MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule renderingEPSS 0.3%CVE-2026-44206MEDIUMFrappe: DB Schema Enumeration via Frappe-Authorization-SourceEPSS 0.3%CVE-2025-58439HIGHERP: Possibility of SQL injection due to missing validationEPSS 0.3%CVE-2026-49394HIGHFrappe: Auth. bypass via update_pageEPSS 0.3%CVE-2026-44447HIGHERPNext: Possibility of SQL Injection due to missing validationEPSS 0.3%CVE-2025-66205HIGHFrappe has the possibility of SQL Injection due to improper validationsEPSS 0.3%CVE-2026-39405CRITICALFrappe has Path Transversal via SCORMEPSS 0.3%CVE-2025-53545MEDIUMPress has a potential 2FA bypassEPSS 0.3%CVE-2026-26977MEDIUMFrappe Learning Management System exposes details of unpublished courses to unauthorized usersEPSS 0.3%CVE-2026-31877CRITICALFrappe SQL Injection due to improper field sanitizationEPSS 0.3%CVE-2026-44442CRITICALERPNext: Unauthorised Document modification due to missing validationEPSS 0.3%CVE-2026-47182MEDIUMFrappe: Broken Access Control on Private FilesEPSS 0.3%CVE-2026-44975MEDIUMFrappe: Missing authorization on reset form toursEPSS 0.3%