Vulnerabilidades em Frappe
126 resultadosAnálise Vexday
Frappe apresenta 22 vulnerabilidades catalogadas, com 16 descobertas nos últimos 90 dias, indicando ritmo acelerado de exposição de fraquezas. Embora nenhuma esteja sob exploração ativa no momento, a ausência de críticas (CVSS) não diminui a relevância do padrão dominante de XSS (CWE-79), que historicamente é vetor comum de comprometimento. O volume recente sugere atenção continuada a atualizações de segurança.
CVE-2026-44208MEDIUMFrappe: IDOR in `submit_discussion()`EPSS 0.3%CVE-2026-44207MEDIUMFrappe: Insecure Direct Object Reference for email accountsEPSS 0.3%CVE-2025-55732HIGHFrappe has the possibility of SQL Injection due to improper validationsEPSS 0.3%CVE-2026-32954HIGHERP has a possibility SQL Injection vulnerability due to missing validationEPSS 0.3%CVE-2026-50699MEDIUMFrappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule renderingEPSS 0.3%CVE-2025-58439HIGHERP: Possibility of SQL injection due to missing validationEPSS 0.3%CVE-2026-44206MEDIUMFrappe: DB Schema Enumeration via Frappe-Authorization-SourceEPSS 0.3%CVE-2026-49394HIGHFrappe: Auth. bypass via update_pageEPSS 0.3%CVE-2026-44447HIGHERPNext: Possibility of SQL Injection due to missing validationEPSS 0.3%CVE-2025-66205HIGHFrappe has the possibility of SQL Injection due to improper validationsEPSS 0.3%CVE-2026-39405CRITICALFrappe has Path Transversal via SCORMEPSS 0.3%CVE-2025-53545MEDIUMPress has a potential 2FA bypassEPSS 0.3%CVE-2026-26977MEDIUMFrappe Learning Management System exposes details of unpublished courses to unauthorized usersEPSS 0.3%CVE-2026-31877CRITICALFrappe SQL Injection due to improper field sanitizationEPSS 0.3%CVE-2026-44442CRITICALERPNext: Unauthorised Document modification due to missing validationEPSS 0.3%CVE-2026-47182MEDIUMFrappe: Broken Access Control on Private FilesEPSS 0.3%CVE-2026-44975MEDIUMFrappe: Missing authorization on reset form toursEPSS 0.3%CVE-2026-47422MEDIUMFrappe: Unrestricted API access to save_reportEPSS 0.3%CVE-2026-44976MEDIUMFrappe: IDOR in update_onboarding_stepEPSS 0.3%CVE-2026-29081MEDIUMFrappe: Possibility of SQL Injection due to improper fieldname sanitizationEPSS 0.3%