Vulnerabilities in Frappe
132 resultsVexday analysis
Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.
CVE-2026-50705MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline renderingEPSS 0.3%CVE-2026-50710MEDIUMFrappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_configEPSS 0.3%CVE-2026-50711MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields renderingEPSS 0.3%CVE-2025-52896HIGHFrappe authenticated XSS via data importEPSS 0.2%CVE-2025-62407MEDIUMFrappe has an Open Redirect on Login PageEPSS 0.2%CVE-2026-13227HIGHERPNext v16.25.0 - Improper authorization in Prospect opportunities APIEPSS 0.2%CVE-2026-42840MEDIUMERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literalsEPSS 0.2%CVE-2026-50709MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Notifications Events color renderingEPSS 0.2%CVE-2026-50708MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result renderingEPSS 0.2%CVE-2026-50712MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Tree View node label renderingEPSS 0.2%CVE-2026-50703MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Desktop Icon label renderingEPSS 0.2%CVE-2026-40888MEDIUMFrappe HR vulnerable to Improper Access ControlEPSS 0.2%CVE-2026-40889MEDIUMFrappe HR has Improper Access Control on FilesEPSS 0.2%CVE-2026-41581MEDIUMFrappe Vulnerable to Possible SQL Injection via get_blog_listEPSS 0.2%CVE-2025-59415MEDIUMFrappe Learning vulnerable to Malicious Content upload via Profile bio fieldEPSS 0.2%CVE-2026-66058MEDIUMFrappe: Unrestricted access to a Document Follow APIEPSS 0.2%CVE-2026-44445MEDIUMERPNext: XML External Entity (XEE) Reference Vulnerability in the EDI ModuleEPSS 0.2%CVE-2026-39385HIGHFrappe LMS enrollment bypass in paid courses via unrelated batchEPSS 0.2%CVE-2026-41320MEDIUMFrappe HR has possibility of SQL Injection due to improper field sanitizationEPSS 0.2%CVE-2026-12895HIGHSQL Injection in Frappe's ERPNextEPSS 0.2%