← Back

Frappe

frappe

Vendor: Frappe • 48 CVEs

CVEs (48)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Frappe
1Frappe
Jun 17, 2026
Dec 11, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.
1Frappe
1Frappe
Jun 17, 2026
Dec 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security.
1Frappe
1Frappe
Jun 17, 2026
Mar 18, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) i...Show more
In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files.Show less
1Frappe
1Frappe
Jun 17, 2026
Aug 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.
1Frappe
1Frappe
Jun 17, 2026
Aug 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
1Frappe
1Frappe
Jun 17, 2026
Aug 12, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.
1Frappe
1Frappe
Jun 17, 2026
Aug 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.
1Frappe
1Frappe
May 13, 2026
Oct 5, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
[ERPNext][Frappe Version <= 7.1.27] SQL injection vulnerability in frappe.share.get_users allows remote authenticated users to execute arbitrary SQL commands via the fields parameter.