Vulnerabilities in Frappe

126 results
Vexday analysis

Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.

CVE-2026-3837MEDIUMFrappe Framework 16.10.0 - Stored DOM XSS in Multiple Field FormattersEPSS 0.2%CVE-2026-34606MEDIUMStored XSS in Frappe LMSEPSS 0.2%CVE-2026-31878MEDIUMFrappe: Possible SSRF by any authenticated userEPSS 0.2%CVE-2026-26031LOWFrappe LMS affected by unauthorised user was able to access the full list of batch enrolled studentsEPSS 0.2%CVE-2025-68928MEDIUMFrappe CRM vulnerable to authenticated XSS via website fieldEPSS 0.2%CVE-2025-62779LOWFrappe Learning users were able to add HTML through input fields in the Job FormEPSS 0.2%CVE-2026-28436LOWFrappe: Stored XSS in avatar_macro.htmlEPSS 0.2%CVE-2025-64707LOWFrappe LMS revoking access did not show immediate effect as roles were cachedEPSS 0.2%CVE-2026-41317MEDIUMFrappe Press has an unsafe HTTP method / CSRF-adjacent issue on API secret generationEPSS 0.2%CVE-2026-44441MEDIUMERPNext: Possible SSRF by any authenticated userEPSS 0.2%CVE-2026-25956MEDIUMFrappe Affected by XSS and Open Redirect in Sign UpEPSS 0.2%CVE-2026-41430LOWPress vulnerable to reflected XSS on login redirectionEPSS 0.2%CVE-2025-67730MEDIUMFrappe authenticated users can execute XSS through form description fieldsEPSS 0.1%CVE-2025-67734MEDIUMFrappe Authenticated Users can Execute JavaScript through its Job FormEPSS 0.1%CVE-2026-44448MEDIUMERPNext: Unauthorised Document modification due to missing validationEPSS 0.1%CVE-2026-23497LOWFrappe LMS has a Stored XSS via Unsanitized Image Filename in Course and Jobs PagesEPSS 0.1%CVE-2026-46546LOWFrappe LMS: HTML injection in user-controlled metadataEPSS 0.1%CVE-2026-55242HIGHERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefixEPSS 0.1%CVE-2026-31879MEDIUMFrappe Workspace modification and stored XSS due to improper resource ownership checksEPSS 0.1%CVE-2026-47765HIGHFrappe: Lack of Permissions in restore/bulk_restoreEPSS