Vulnerability index

Browse CVEs

121 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Learning MEDIUM 5.4
CVE-2026-46546

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user…

Fix: 2.52.0+
Fix from $1,600 2026-06-10
Erpnext CRITICAL 9.9
CVE-2026-44442

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks…

Fix: 16.9.1+
Fix from $2,300 2026-05-13
Erpnext HIGH 7.5
CVE-2026-44446

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection t…

Fix: 15.104.3 / 16.14.0+
Fix from $1,950 2026-05-13
Erpnext HIGH 7.5
CVE-2026-44447

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through special…

Fix: 16.9.0+
Fix from $1,950 2026-05-13
Erpnext MEDIUM 6.5
CVE-2026-44445

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (X…

Fix: 15.104.3 / 16.12.0+
Fix from $1,600 2026-05-13
Erpnext MEDIUM 6.5
CVE-2026-44448

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper author…

Fix: 15.102.0 / 16.11.0+
Fix from $1,600 2026-05-13
Erpnext MEDIUM 5.7
CVE-2026-44440

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restric…

Fix: 15.101.1 / 16.10.0+
Fix from $1,600 2026-05-13
Erpnext CRITICAL 9.8
CVE-2026-38431

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates ca…

Fix: after 15.103.1
Fix from $2,300 2026-05-05
Erpnext MEDIUM 6.1
CVE-2026-38432

ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit …

Fix: after 15.103.1
Fix from $1,600 2026-05-05
Erpnext HIGH 8.8
CVE-2023-54345

Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role …

No fix yet
Fix from $1,950 2026-05-05
Press MEDIUM 6.1
CVE-2026-41430

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect para…

Fix: 0.16.0+
Fix from $1,600 2026-04-24
Press HIGH 7.5
CVE-2026-41317

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).`press.api.acc…

Fix: 0.9.0+
Fix from $1,950 2026-04-24
Frappe MEDIUM 5.4
CVE-2026-3837

An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the aff…

Patch available
Fix from $1,600 2026-04-22
Frappe MEDIUM 5.4
CVE-2026-3673

An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where…

No fix yet
Fix from $1,600 2026-04-22
Frappe Hr MEDIUM 6.5
CVE-2026-41320

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a …

Fix: 14.38.1 / 15.54.0+
Fix from $1,600 2026-04-21
Frappe Hr MEDIUM 6.5
CVE-2026-40888

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role…

Fix: 15.58.1 / 16.4.1+
Fix from $1,600 2026-04-21
Frappe Hr MEDIUM 6.5
CVE-2026-40889

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthor…

Fix: 15.58.2 / 16.4.2+
Fix from $1,600 2026-04-21
Erpnext CRITICAL 9.1
CVE-2026-31017

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where us…

Mitigation only
Fix from $2,300 2026-04-08
Frappe CRITICAL 9.1
CVE-2026-39351

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.

Fix: 15.104.0 / 16.14.0+
Fix from $2,300 2026-04-07
Frappe CRITICAL 9.8
CVE-2026-35614

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_update. This vulnerability is fix…

Fix: 15.104.0 / 16.14.0+
Fix from $2,300 2026-04-07
Learning MEDIUM 6.1
CVE-2026-34606

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, …

Fix: 2.48.0+
Fix from $1,600 2026-04-02
Erpnext HIGH 7.5
CVE-2026-32954

ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-…

Fix: 15.100.0 / 16.8.0+
Fix from $1,950 2026-03-20
Frappe CRITICAL 9.8
CVE-2026-31877

Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result i…

Fix: 14.99.0 / 15.84.0+
Fix from $2,300 2026-03-11
Frappe MEDIUM 5.4
CVE-2026-31879

Frappe is a full-stack web application framework. Prior to 14.100.2, 15.101.0, and 16.10.0, due to a lack of validation and improper permission check…

Fix: 14.100.2 / 15.101.0+
Fix from $1,600 2026-03-11
Frappe MEDIUM 5.0
CVE-2026-31878

Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a crafted request to an endpoi…

Fix: 14.100.1 / 15.100.0+
Fix from $1,600 2026-03-11
Frappe HIGH 8.8
CVE-2026-29081

Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to SQL injection through specia…

Fix: 14.100.1+
Fix from $1,950 2026-03-05
Frappe HIGH 7.2
CVE-2026-28436

Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted image URL that results in XSS…

Fix: 15.102.0 / 16.11.0+
Fix from $1,950 2026-03-05
Frappe HIGH 7.1
CVE-2026-29077

Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation when sharing documents, a user …

Fix: 14.100.0 / 15.98.0+
Fix from $1,950 2026-03-05
Erpnext CRITICAL 9.1
CVE-2026-27471

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lack…

Fix: 15.98.1 / 16.6.1+
Fix from $2,300 2026-02-21
Learning MEDIUM 5.3
CVE-2026-26977

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized use…

Fix: 2.45.0+
Fix from $1,600 2026-02-20