CVE-2025-30212Medium▾ SunlitFrappe has possibility of SQL injection due to improper validations
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.4%
An SQL Injection vulnerability has been identified in Frappe Framework which could allow a malicious actor to access sensitive information.
Upgrading is required, no other workaround is present.
Thanks to Thanh of Calif.io for reporting the issue
frappe < 14.89.0frappe >= 15.0.0, < 15.51.0Upgrade to a patched release:
frappe 14.89.0frappe 15.51.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-30213MediumFrappe has Possibility of Remote Code Execution due to improper validation
CVE-2025-30214HighFrappe vulnerable to information disclosure leading to account takeover
CVE-2025-30217MediumFrappe has possibility of SQL injection due to improper validations
CVE-2023-51769Medium· 6.1Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
CVE-2026-96672Medium· 6.4Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call()
CVE-2026-94113Medium· 6.5Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions