← Back

Frappe

frappe

131 CVEs • 7 products

Products (7)

Click to collapse
Toggle
Erpnext
erpnext
Frappe
frappe
Learning
learning
Frappe Hr
frappe_hr
Frappe Crm
frappe_crm
Press
press
Helpdesk
helpdesk

CVEs (131)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Frappe
1Frappe
Jun 17, 2026
Aug 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.
1Frappe
1Frappe
Jun 17, 2026
Aug 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
1Frappe
1Frappe
Jun 17, 2026
Aug 12, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.
1Frappe
1Frappe
Jun 17, 2026
Aug 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.
1Frappe
1Erpnext
Nov 21, 2024
Dec 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, many ERPNext sites allow account creation via the web. No special privileg...Show more
A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, many ERPNext sites allow account creation via the web. No special privileges are needed to conduct the attack. By calling a JavaScript function that calls a server-side Python function with carefully chosen arguments, a SQL attack can be carried out which allows SQL queries to be constructed to return any columns from any tables in the database. This is related to /api/resource/Item?fields= URIs, frappe.get_list, and frappe.call.Show less
2Erpnext
Frappe
2Erpnext
Erpnext
May 8, 2026
Sep 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The order_by parameter can be used to...Show more
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The order_by parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.Show less
2Erpnext
Frappe
2Erpnext
Erpnext
May 8, 2026
Sep 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be...Show more
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.Show less
2Erpnext
Frappe
2Erpnext
Erpnext
May 8, 2026
Sep 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The employee and sort_order parameter...Show more
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The employee and sort_order parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.Show less
2Erpnext
Frappe
2Erpnext
Erpnext
May 8, 2026
Sep 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The searchfield parameter can be used...Show more
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The searchfield parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.Show less
1Frappe
1Erpnext
Nov 21, 2024
May 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
1Frappe
1Frappe
May 13, 2026
Oct 5, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
[ERPNext][Frappe Version <= 7.1.27] SQL injection vulnerability in frappe.share.get_users allows remote authenticated users to execute arbitrary SQL commands via the fields parameter.