Vulnerability index

Browse CVEs

121 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Learning MEDIUM 5.3
CVE-2026-26031

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified…

Fix: 2.44.0+
Fix from $1,600 2026-02-11
Frappe MEDIUM 6.1
CVE-2026-25956

Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious signup URL for a frappe site whi…

Fix: 14.99.14 / 15.94.0+
Fix from $1,600 2026-02-10
Erpnext MEDIUM 5.4
CVE-2025-65923

A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1 when using the Update Existi…

Fix: after 15.88.1
Fix from $1,600 2026-02-03
Learning MEDIUM 5.4
CVE-2026-23497

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and earlier, there is a stored XSS v…

Fix: 2.45.0+
Fix from $1,600 2026-01-14
Frappe HIGH 7.5
CVE-2025-68953

Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests that are vulnerable to path …

Fix: 14.99.6 / 15.88.1+
Fix from $1,950 2026-01-05
Frappe CRITICAL 9.0
CVE-2025-68929

Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tri…

Fix: 14.99.6 / 15.88.1+
Fix from $2,300 2025-12-29
Frappe Crm MEDIUM 5.4
CVE-2025-68928

Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could set crafted URLs in a website …

Fix: 1.56.2+
Fix from $1,600 2025-12-29
Erpnext CRITICAL 9.6
CVE-2025-67289

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploadin…

No fix yet
Fix from $2,300 2025-12-22
Erpnext HIGH 8.8
CVE-2025-66437

An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function rend…

Fix: after 15.89.0
Fix from $1,950 2025-12-15
Erpnext HIGH 8.8
CVE-2025-66438

A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, th…

Fix: after 15.89.0
Fix from $1,950 2025-12-15
Erpnext HIGH 8.8
CVE-2025-66439

An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.accounts.doctype.payment_entry.p…

Fix: after 15.89.0
Fix from $1,950 2025-12-15
Erpnext HIGH 8.8
CVE-2025-66440

An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/accounts/doctype/payment_entry/p…

Fix: after 15.89.0
Fix from $1,950 2025-12-15
Erpnext HIGH 8.8
CVE-2025-66434

An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function r…

Fix: after 15.89.0
Fix from $1,950 2025-12-15
Learning MEDIUM 5.4
CVE-2025-67734

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allowed authenticated…

Fix: 2.42.0+
Fix from $1,600 2025-12-12
Learning MEDIUM 5.4
CVE-2025-67730

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allow authenticated u…

Fix: 2.42.0+
Fix from $1,600 2025-12-12
Helpdesk HIGH 8.8
CVE-2025-10655

SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL state…

Patch available
Fix from $1,950 2025-12-09
Learning MEDIUM 6.5
CVE-2025-66581

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, a flaw in the server-side aut…

Fix: 2.41.0+
Fix from $1,600 2025-12-05
Erpnext CRITICAL 9.0
CVE-2025-65267

In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. …

Mitigation only
Fix from $2,300 2025-12-03
Frappe CRITICAL 9.8
CVE-2025-66205

Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to…

Fix: 14.99.2 / 15.86.0+
Fix from $2,300 2025-12-01
Frappe HIGH 8.6
CVE-2025-66206

Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path traversal attacks, wherein s…

Fix: 14.99.2 / 15.86.0+
Fix from $1,950 2025-12-01
Frappe Crm HIGH 8.8
CVE-2025-11461

Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. Thi…

Patch available
Fix from $1,950 2025-11-26
Learning MEDIUM 5.4
CVE-2025-64707

Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, when admins rev…

Fix: 2.41.0+
Fix from $1,600 2025-11-12
Learning MEDIUM 5.4
CVE-2025-62779

Frappe Learning is a learning system that helps users structure their content. In Frappe Learning 2.39.1 and earlier, users were able to add HTML thr…

Fix: 2.39.2+
Fix from $1,600 2025-10-27
Learning MEDIUM 5.3
CVE-2025-62778

Frappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to a…

Fix: 2.39.2+
Fix from $1,600 2025-10-27
Frappe MEDIUM 6.1
CVE-2025-62407

Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the l…

Fix: 14.98.0 / 15.83.0+
Fix from $1,600 2025-10-16
Learning MEDIUM 5.3
CVE-2025-62158

Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments upl…

Patch available
Fix from $1,600 2025-10-10
Learning MEDIUM 6.1
CVE-2025-11282

A vulnerability was found in Frappe LMS 2.34.x/2.35.0. The impacted element is an unknown function of the component Incomplete Fix CVE-2025-55006. Pe…

Fix: after 2.35.0
Fix from $1,600 2025-10-05
Learning MEDIUM 5.0
CVE-2025-11281

A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished C…

No fix yet
Fix from $1,600 2025-10-05
Erpnext MEDIUM 6.5
CVE-2025-56380

Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endp…

No fix yet
Fix from $1,600 2025-10-02
Erpnext MEDIUM 6.5
CVE-2025-56381

ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the orde…

No fix yet
Fix from $1,600 2025-10-02