VulnSea

frappe vulnerabilities

CVEs whose affected-version data names the frappe package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2023-51769Medium· 6.1
1w ago

Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.

Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.

SunlitFrappe · FrappeEPSS 0.19%via NVD
CVE-2026-31017Critical· 9.1
5mo ago

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When genera…

Midnightfrappe · erpnextEPSS 0.24%via NVD
CVE-2025-67289Critical· 9.6
9mo ago

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

Midnightfrappe · erpnextEPSS 0.46%via NVD
CVE-2025-30217Medium
1y ago

Frappe has possibility of SQL injection due to improper validations

Frappe has possibility of SQL injection due to improper validations

Sunlitfrappe · frappeEPSS 0.35%via OSV
CVE-2025-30213Medium
1y ago

Frappe has Possibility of Remote Code Execution due to improper validation

Frappe has Possibility of Remote Code Execution due to improper validation

Sunlitfrappe · frappeEPSS 0.71%via OSV
CVE-2025-30214High
1y ago

Frappe vulnerable to information disclosure leading to account takeover

Frappe vulnerable to information disclosure leading to account takeover

Twilightfrappe · frappeEPSS 0.40%via OSV
CVE-2025-30212Medium
1y ago

Frappe has possibility of SQL injection due to improper validations

Frappe has possibility of SQL injection due to improper validations

Sunlitfrappe · frappeEPSS 0.43%via OSV
frappe vulnerabilities (CVEs) · VulnSea