{"id":"CVE-2025-30212","aliases":["GHSA-3hj6-r5c9-q8f3","PYSEC-2026-1390"],"title":"Frappe has possibility of SQL injection due to improper validations","summary":"Frappe has possibility of SQL injection due to improper validations","severity":"medium","vendor":"frappe","product":"frappe","ecosystem":"pip","affected":["frappe < 14.89.0","frappe >= 15.0.0, < 15.51.0"],"patched":["frappe 14.89.0","frappe 15.51.0"],"published":"2025-03-25","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-3hj6-r5c9-q8f3","references":[{"url":"https://github.com/frappe/frappe/security/advisories/GHSA-3hj6-r5c9-q8f3"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30212"},{"url":"https://github.com/frappe/frappe/commit/27f13437db161a173137d91cd07d0f9287d7c556"},{"url":"https://github.com/frappe/frappe/commit/2ebd88520ecfa9bb7d3392b7de8c8f94a86ec05c"},{"url":"https://github.com/frappe/frappe"}],"tags":["osv","pip"],"epss":0.00426,"epssPercentile":0.36497,"ingestedAt":"2026-07-08T18:25:44.917Z","slug":"CVE-2025-30212","body":"## Overview\n\n### Impact\nAn SQL Injection vulnerability has been identified in Frappe Framework which could allow a malicious actor to access sensitive information.\n\n### Workarounds\nUpgrading is required, no other workaround is present.\n\n### Credits\n\nThanks to Thanh of Calif.io for reporting the issue\n\n## Affected packages\n\n- `frappe < 14.89.0`\n- `frappe >= 15.0.0, < 15.51.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `frappe 14.89.0`\n- `frappe 15.51.0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}