Vulnerability index

Browse CVEs

27 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-54345 Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role … Erpnext No fix yet Fix from $1,9502026-05-05 MEDIUM 5.4 CVE-2026-3673 An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where… Frappe No fix yet Fix from $1,6002026-04-22 CRITICAL 9.1 CVE-2026-31017 A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where us… Erpnext Mitigation only Fix from $2,3002026-04-08 CRITICAL 9.6 CVE-2025-67289 An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploadin… Erpnext No fix yet Fix from $2,3002025-12-22 CRITICAL 9.0 CVE-2025-65267 In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. … Erpnext Mitigation only Fix from $2,3002025-12-03 MEDIUM 5.0 CVE-2025-11281 A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished C… Learning No fix yet Fix from $1,6002025-10-05 MEDIUM 6.5 CVE-2025-56380 Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endp… Erpnext No fix yet Fix from $1,6002025-10-02 MEDIUM 6.5 CVE-2025-56381 ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the orde… Erpnext No fix yet Fix from $1,6002025-10-02 MEDIUM 5.4 CVE-2025-56379 A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or H… Erpnext No fix yet Fix from $1,6002025-10-02 HIGH 8.1 CVE-2025-28062 A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unau… Erpnext No fix yet Fix from $1,9502025-05-05 MEDIUM 6.5 CVE-2022-41712 Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correc… Frappe No fix yet Fix from $1,6002022-11-25 MEDIUM 6.1 CVE-2022-28598 Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is pla… Erpnext No fix yet Fix from $1,6002022-08-22 HIGH 8.8 CVE-2020-6145 An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause … Erpnext No fix yet Fix from $1,9502020-08-10 MEDIUM 6.1 CVE-2019-20514 ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI. Erpnext No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2019-20515 ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI. Erpnext No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2019-20516 ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI. Erpnext No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2019-20517 ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI. Erpnext No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2019-20518 ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI. Erpnext No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2019-20519 ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address. Erpnext No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2019-20520 ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI. Erpnext No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2019-20521 ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI. Erpnext No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2019-20511 ERPNext 11.1.47 allows blog?blog_category= Frame Injection. Erpnext No fix yet Fix from $1,6002020-03-18 HIGH 8.8 CVE-2018-3882 An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio… Erpnext No fix yet Fix from $1,9502018-09-12 HIGH 8.8 CVE-2018-3883 An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio… Erpnext No fix yet Fix from $1,9502018-09-12 HIGH 8.8 CVE-2018-3884 An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio… Erpnext No fix yet Fix from $1,9502018-09-12 HIGH 8.8 CVE-2018-3885 An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio… Erpnext No fix yet Fix from $1,9502018-09-12 MEDIUM 6.1 CVE-2018-11339 An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment. Erpnext No fix yet Fix from $1,6002018-05-22