frappe has 12 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 5 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 4. The median CVSS is 7.9 (high), with 3 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-79 (3). Most affected products: ERPNext (5), Frappe (5), hrms (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.9
- Publish → KEV
- —
- Last 90 days
- 5 prev 1
Weakness classes
Products
- ERPNext 5
- Frappe 5
- hrms 1
- lms 1
Worst active — by depth score
CVE-2026-65974Critical· 9.9ERPNext is a free and open source Enterprise Resource Planning tool55CVE-2025-67289Critical· 9.6An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.53CVE-2026-31017Critical· 9.1A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF50CVE-2026-54343High· 8.7Frappe Learning Management System (LMS) is a learning system that helps users structure their content48CVE-2022-28598Medium· 6.1Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.46
frappe vulnerabilities
CVEs affecting frappe, newest first. Open any entry for full detail, references, and exploit status.
12 CVEsRSS
CVE-2026-94113Medium· 6.5Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise…
CVE-2026-54343High· 8.7Frappe Learning Management System (LMS) is a learning system that helps users structure their content
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The …
CVE-2026-54524High· 7.1Frappe HR is an open-source human resources management solution (HRMS)
Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Payment Mode report. In hrms/payroll/repo…
CVE-2023-51769Medium· 6.1Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
CVE-2026-65974Critical· 9.9ERPNext is a free and open source Enterprise Resource Planning tool
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without fo…
CVE-2026-31017Critical· 9.1A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF
A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When genera…
CVE-2025-67289Critical· 9.6An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
CVE-2025-30217MediumFrappe has possibility of SQL injection due to improper validations
Frappe has possibility of SQL injection due to improper validations
CVE-2025-30213MediumFrappe has Possibility of Remote Code Execution due to improper validation
Frappe has Possibility of Remote Code Execution due to improper validation
CVE-2025-30214HighFrappe vulnerable to information disclosure leading to account takeover
Frappe vulnerable to information disclosure leading to account takeover
CVE-2025-30212MediumFrappe has possibility of SQL injection due to improper validations
Frappe has possibility of SQL injection due to improper validations
CVE-2022-28598Medium· 6.1PoCFrappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.