CVE-2023-51769Medium· 6.1▾ SunlitFrappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-30213MediumFrappe has Possibility of Remote Code Execution due to improper validation
CVE-2025-30214HighFrappe vulnerable to information disclosure leading to account takeover
CVE-2025-30217MediumFrappe has possibility of SQL injection due to improper validations
CVE-2025-30212MediumFrappe has possibility of SQL injection due to improper validations
CVE-2022-28598Medium· 6.1Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2025-67289Critical· 9.6An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.