CVE-2025-30214High▾ TwilightFrappe vulnerable to information disclosure leading to account takeover
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.4%
Making crafted requests could lead to information disclosure that could further lead to account takeover.
There's no workaround to fix this without upgrading.
Thanks to Thanh of Calif.io for reporting the issue
frappe < 14.89.0frappe >= 15.0.0, < 15.51.0Upgrade to a patched release:
frappe 14.89.0frappe 15.51.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-30213MediumFrappe has Possibility of Remote Code Execution due to improper validation
CVE-2025-30217MediumFrappe has possibility of SQL injection due to improper validations
CVE-2025-30212MediumFrappe has possibility of SQL injection due to improper validations
CVE-2023-51769Medium· 6.1Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
CVE-2026-96672Medium· 6.4Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call()
CVE-2026-94113Medium· 6.5Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions