CVE-2025-30217Medium▾ SunlitFrappe has possibility of SQL injection due to improper validations
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.4%
SQL injection could be achieved via a specially crafted request, which could allow malicious person to gain access to sensitive information.
Upgrading is required, no other workaround is present.
frappe < 14.93.2frappe >= 15.0.0, < 15.55.0Upgrade to a patched release:
frappe 14.93.2frappe 15.55.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-30213MediumFrappe has Possibility of Remote Code Execution due to improper validation
CVE-2025-30214HighFrappe vulnerable to information disclosure leading to account takeover
CVE-2025-30212MediumFrappe has possibility of SQL injection due to improper validations
CVE-2026-81731Medium· 5.4Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description
CVE-2023-51769Medium· 6.1Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
CVE-2026-96672Medium· 6.4Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call()