Vulnerabilities in Frappe

126 results
Vexday analysis

Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.

CVE-2025-62158LOWFrappe had attachments made by students to their assignments of type Text set to publicEPSS 0.3%CVE-2026-50701MEDIUMFrappe Framework 17.0.0-dev - Reflected DOM XSS in dashboard-view breadcrumb renderingEPSS 0.3%CVE-2026-44446HIGHERPNext: Possibility of SQL Injection due to missing validationEPSS 0.3%CVE-2026-39415MEDIUMFrappe Learning Management System has Client-Side Manipulation of Quiz ScoresEPSS 0.3%CVE-2025-55006MEDIUMFrappe Learning Holds Potential for Malicious SVG Upload in Image Upload FeatureEPSS 0.3%CVE-2026-42839MEDIUMERPNext 16.16.0 - Stored XSS in POS cart item renderingEPSS 0.3%CVE-2026-35614CRITICALFrappe has a SQL injection in bulk_updateEPSS 0.3%CVE-2026-50026MEDIUMFrappe: Lack of permissions checks in 'relink' and 'set_email_password' endpointsEPSS 0.3%CVE-2026-39351MEDIUMFrappe allows unrestricted Doctype access via API exploitEPSS 0.3%CVE-2026-53568MEDIUMFrappe: Stored XSS in Frappe Report/List View via 'set_link_title_field_value'EPSS 0.3%CVE-2026-47739MEDIUMFrappe: Stored XSS in NoteEPSS 0.3%CVE-2026-44205MEDIUMFrappe: Stored Cross-Site Scripting (XSS) in User Profile through Image UploadEPSS 0.3%CVE-2026-50705MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline renderingEPSS 0.3%CVE-2026-50710MEDIUMFrappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_configEPSS 0.3%CVE-2026-50698MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Audit Trail template renderingEPSS 0.3%CVE-2026-50711MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields renderingEPSS 0.3%CVE-2026-50704MEDIUMFrappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs renderingEPSS 0.3%CVE-2026-50700MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in frappe.get_avatar image renderingEPSS 0.3%CVE-2025-52896HIGHFrappe authenticated XSS via data importEPSS 0.2%CVE-2025-62407MEDIUMFrappe has an Open Redirect on Login PageEPSS 0.2%