VulnSea

frappe has 12 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 5 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 4. The median CVSS is 7.9 (high), with 3 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-79 (3). Most affected products: ERPNext (5), Frappe (5), hrms (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.9
Publish → KEV
Last 90 days
5 prev 1

Products

  • ERPNext 5
  • Frappe 5
  • hrms 1
  • lms 1
12
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

frappe vulnerabilities

CVEs affecting frappe, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

CVE-2026-94113Medium· 6.5
yesterday

Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions

Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise…

SunlitFrappe · ERPNextEPSS 0.24%via NVD
CVE-2026-54343High· 8.7
4d ago

Frappe Learning Management System (LMS) is a learning system that helps users structure their content

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The …

Twilightfrappe · lmsEPSS 0.48%via NVD
CVE-2026-54524High· 7.1
4d ago

Frappe HR is an open-source human resources management solution (HRMS)

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Payment Mode report. In hrms/payroll/repo…

Twilightfrappe · hrmsEPSS 0.28%via NVD
CVE-2023-51769Medium· 6.1
1w ago

Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.

Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.

SunlitFrappe · FrappeEPSS 0.19%via NVD
CVE-2026-65974Critical· 9.9
1mo ago

ERPNext is a free and open source Enterprise Resource Planning tool

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without fo…

Midnightfrappe · erpnextEPSS 0.56%via NVD
CVE-2026-31017Critical· 9.1
5mo ago

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When genera…

Midnightfrappe · erpnextEPSS 0.24%via NVD
CVE-2025-67289Critical· 9.6
9mo ago

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

Midnightfrappe · erpnextEPSS 0.46%via NVD
CVE-2025-30217Medium
1y ago

Frappe has possibility of SQL injection due to improper validations

Frappe has possibility of SQL injection due to improper validations

Sunlitfrappe · frappeEPSS 0.35%via OSV
CVE-2025-30213Medium
1y ago

Frappe has Possibility of Remote Code Execution due to improper validation

Frappe has Possibility of Remote Code Execution due to improper validation

Sunlitfrappe · frappeEPSS 0.71%via OSV
CVE-2025-30214High
1y ago

Frappe vulnerable to information disclosure leading to account takeover

Frappe vulnerable to information disclosure leading to account takeover

Twilightfrappe · frappeEPSS 0.40%via OSV
CVE-2025-30212Medium
1y ago

Frappe has possibility of SQL injection due to improper validations

Frappe has possibility of SQL injection due to improper validations

Sunlitfrappe · frappeEPSS 0.43%via OSV
CVE-2022-28598Medium· 6.1PoC
4y ago

Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.

Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.

Twilightfrappe · erpnextEPSS 4.1%via NVD
frappe vulnerabilities (CVEs) · VulnSea