Vulnerabilidades em Frappe
126 resultadosAnálise Vexday
Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.
CVE-2025-30214HIGHFrappe vulnerable to information disclosure leading to account takeoverEPSS 0.4%CVE-2025-52898HIGHFrappe account takeover via password reset token leakageEPSS 0.4%CVE-2024-24812MEDIUMFrappe Authenticated Reflected Cross site scripting (XSS) in portal pagesEPSS 0.4%CVE-2025-11283MEDIUMFrappe LMS Course cross site scriptingEPSS 0.4%CVE-2025-68953HIGHCertain Frappe requests are vulnerable to Path TraversalEPSS 0.4%CVE-2024-50356NONEPress has a potential 2FA bypassEPSS 0.4%CVE-2026-48127MEDIUMFrappe: Arbitrary Attachment Injection via add_attachments and upload_fileEPSS 0.4%CVE-2026-44440MEDIUMERPNext: Path Traversal Leading to Sensitive File ExposureEPSS 0.4%CVE-2025-11282MEDIUMFrappe LMS Incomplete Fix CVE-2025-55006 cross site scriptingEPSS 0.4%CVE-2025-55731MEDIUMFrappe has the possibility of Authenticated SQL Injection due to improper validationsEPSS 0.4%CVE-2026-58503MEDIUMFrappe: Unauthenticated User Enumeration via reset_passwordEPSS 0.4%CVE-2025-52895HIGHFrappe possibility of SQL injection due to improper validationsEPSS 0.4%CVE-2023-42807MEDIUMFrappe LMS SQL Injection Issue on People PageEPSS 0.3%CVE-2025-58375HIGHFrappe has potential SQL Injection due to missing validationEPSS 0.3%CVE-2025-11461HIGHFrappe CRM 1.53.1 — Multiple SQL Injections in Dashboard ControllerEPSS 0.3%CVE-2025-30217MEDIUMFrappe has possibility of SQL injection due to improper validationsEPSS 0.3%CVE-2026-41482HIGHFrappe: Possible Path Traversal and Local File Inclusion via Chrome PDF GeneratorEPSS 0.3%CVE-2025-66206MEDIUMFrappe vulnerable to a path traversal allowing reading certain filesEPSS 0.3%CVE-2025-11281LOWFrappe LMS Unpublished Course courses access controlEPSS 0.3%CVE-2026-27471CRITICALERP: Document access through endpoints due to missing validationEPSS 0.3%