← Back

Erpnext

erpnext

Vendor: Frappe • 59 CVEs

CVEs (59)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Frappe
1Erpnext
Jun 17, 2026
Jun 22, 2022
N/A· v4
N/A· v3
3.5 LOW· v2
ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.
1Frappe
1Erpnext
Jun 17, 2026
Jun 22, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when edit...Show more
In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.Show less
1Frappe
1Erpnext
Jun 17, 2026
Jun 22, 2022
N/A· v4
N/A· v3
3.5 LOW· v2
In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.
1Frappe
1Erpnext
Jun 17, 2026
Aug 10, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to...Show more
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Frappe
1Erpnext
Jun 17, 2026
Mar 19, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.
1Frappe
1Erpnext
Jun 17, 2026
Mar 19, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.
1Frappe
1Erpnext
Jun 17, 2026
Mar 19, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.
1Frappe
1Erpnext
Jun 17, 2026
Mar 19, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
1Frappe
1Erpnext
Jun 17, 2026
Mar 19, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.
1Frappe
1Erpnext
Jun 17, 2026
Mar 19, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.
1Frappe
1Erpnext
Jun 17, 2026
Mar 19, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.
1Frappe
1Erpnext
Jun 17, 2026
Mar 19, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.
1Frappe
1Erpnext
Jun 17, 2026
Mar 18, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ERPNext 11.1.47 allows blog?blog_category= Frame Injection.
1Frappe
1Erpnext
Nov 21, 2024
Dec 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, many ERPNext sites allow account creation via the web. No special privileg...Show more
A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, many ERPNext sites allow account creation via the web. No special privileges are needed to conduct the attack. By calling a JavaScript function that calls a server-side Python function with carefully chosen arguments, a SQL attack can be carried out which allows SQL queries to be constructed to return any columns from any tables in the database. This is related to /api/resource/Item?fields= URIs, frappe.get_list, and frappe.call.Show less
2Erpnext
Frappe
2Erpnext
Erpnext
May 8, 2026
Sep 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The order_by parameter can be used to...Show more
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The order_by parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.Show less
2Erpnext
Frappe
2Erpnext
Erpnext
May 8, 2026
Sep 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be...Show more
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.Show less
2Erpnext
Frappe
2Erpnext
Erpnext
May 8, 2026
Sep 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The employee and sort_order parameter...Show more
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The employee and sort_order parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.Show less
2Erpnext
Frappe
2Erpnext
Erpnext
May 8, 2026
Sep 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The searchfield parameter can be used...Show more
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The searchfield parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.Show less
1Frappe
1Erpnext
Nov 21, 2024
May 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.