CVE-2025-30213Medium▾ SunlitFrappe has Possibility of Remote Code Execution due to improper validation
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
0.7% → 0.7%
A system user was able to create certain documents in a specific way that could lead to RCE.
There's no workaround, an upgrade is required.
Thanks to Thanh of Calif.io for reporting the issue
frappe < 14.91.0frappe >= 15.0.0, < 15.52.0Upgrade to a patched release:
frappe 14.91.0frappe 15.52.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-30214HighFrappe vulnerable to information disclosure leading to account takeover
CVE-2025-30217MediumFrappe has possibility of SQL injection due to improper validations
CVE-2025-30212MediumFrappe has possibility of SQL injection due to improper validations
CVE-2023-51769Medium· 6.1Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
CVE-2026-94113Medium· 6.5Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions
CVE-2026-54343High· 8.7Frappe Learning Management System (LMS) is a learning system that helps users structure their content