Vulnerabilities in Frappe
132 resultsVexday analysis
Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.
CVE-2026-41430LOWPress vulnerable to reflected XSS on login redirectionEPSS 0.2%CVE-2026-44448MEDIUMERPNext: Unauthorised Document modification due to missing validationEPSS 0.1%CVE-2026-23497LOWFrappe LMS has a Stored XSS via Unsanitized Image Filename in Course and Jobs PagesEPSS 0.1%CVE-2026-55242HIGHERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefixEPSS 0.1%CVE-2026-31879MEDIUMFrappe Workspace modification and stored XSS due to improper resource ownership checksEPSS 0.1%CVE-2026-46546LOWFrappe LMS: HTML injection in user-controlled metadataEPSS 0.1%CVE-2026-72906MEDIUMERPNext: Unauthorised triggering of automated emails due to missing validationEPSS —CVE-2026-72907MEDIUMERPNext: Broken Access Control on certain endpointEPSS —CVE-2026-72908MEDIUMERPNext: Possibility of SQL injection due to missing validationEPSS —CVE-2026-72909HIGHERPNext: Broken Access Control on certain endpointsEPSS —CVE-2026-72910HIGHERPNext: Unauthorised modification of master data due to missing validationEPSS —CVE-2026-72911CRITICALERPNext: Possibility of server-side template injection due to missing validationEPSS —