CVE-2025-10655High· 8.8▾ TwilightSQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0.
helpdesk = 1.14.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-23753Medium· 4.8GFI HelpDesk < 4.99.9 Stored XSS via charset Parameter
CVE-2026-23756Medium· 5.4GFI HelpDesk < 4.99.9 Stored XSS via Troubleshooter Step Subject
CVE-2026-23758Medium· 5.1GFI HelpDesk < 4.99.9 Stored XSS via editsubject Parameter
CVE-2026-23752Medium· 4.8GFI HelpDesk < 4.99.9 Stored XSS via companyname Parameter
CVE-2026-23757Medium· 5.4GFI HelpDesk < 4.99.10 Stored XSS via Reports Module
CVE-2026-54524High· 7.1Frappe HR is an open-source human resources management solution (HRMS)