frappe vulnerabilities
CVEs whose affected-version data names the frappe package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
7 CVEsRSS
CVE-2023-51769Medium· 6.1Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
CVE-2026-31017Critical· 9.1A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF
A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When genera…
CVE-2025-67289Critical· 9.6An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
CVE-2025-30217MediumFrappe has possibility of SQL injection due to improper validations
Frappe has possibility of SQL injection due to improper validations
CVE-2025-30213MediumFrappe has Possibility of Remote Code Execution due to improper validation
Frappe has Possibility of Remote Code Execution due to improper validation
CVE-2025-30214HighFrappe vulnerable to information disclosure leading to account takeover
Frappe vulnerable to information disclosure leading to account takeover
CVE-2025-30212MediumFrappe has possibility of SQL injection due to improper validations
Frappe has possibility of SQL injection due to improper validations