Vulnerability index

Browse CVEs

121 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Erpnext MEDIUM 5.4
CVE-2025-56379

A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or H…

No fix yet
Fix from $1,600 2025-10-02
Erpnext HIGH 8.2
CVE-2025-52040

In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attack…

Patch available
Fix from $1,950 2025-10-01
Erpnext HIGH 8.2
CVE-2025-52041

In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reconciliation.py is vulnerable t…

Patch available
Fix from $1,950 2025-10-01
Erpnext HIGH 8.2
CVE-2025-52042

In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/request_for_quotation/request_for_quotation.py is vul…

Patch available
Fix from $1,950 2025-10-01
Erpnext HIGH 8.2
CVE-2025-52039

In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_request/material_request.py is vu…

Patch available
Fix from $1,950 2025-10-01
Erpnext MEDIUM 6.5
CVE-2025-52043

In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_accounts_importer.py is vulnera…

Patch available
Fix from $1,600 2025-09-30
Erpnext MEDIUM 6.5
CVE-2025-52047

In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attac…

Patch available
Fix from $1,600 2025-09-30
Erpnext MEDIUM 6.5
CVE-2025-52049

In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py is vulnerable to SQL Injectio…

Patch available
Fix from $1,600 2025-09-30
Erpnext MEDIUM 6.5
CVE-2025-52050

In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_program/loyalty_program.py is v…

Patch available
Fix from $1,600 2025-09-30
Learning MEDIUM 5.4
CVE-2025-59415

Frappe Learning is a learning system that helps users structure their content. In versions 2.34.1 and below, there is a security vulnerability in Fra…

Fix: 2.35.0+
Fix from $1,600 2025-09-17
Erpnext HIGH 7.5
CVE-2025-52044

In Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is vulnerable to SQL Injection, which allows an attacker to ex…

Patch available
Fix from $1,950 2025-09-16
Frappe MEDIUM 6.5
CVE-2025-52048

In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py` is vulnerable to SQL Inject…

Fix: 14.96.10 / 15.72.0+
Fix from $1,600 2025-09-15
Erpnext CRITICAL 9.1
CVE-2025-58439

ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of paramete…

Fix: 14.89.2 / 15.76.0+
Fix from $2,300 2025-09-06
Frappe HIGH 7.5
CVE-2025-55732

Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted …

Fix: 14.96.15 / 15.74.2+
Fix from $1,950 2025-08-20
Frappe HIGH 8.8
CVE-2025-55731

Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via…

Fix: 14.96.15 / 15.74.2+
Fix from $1,950 2025-08-20
Learning HIGH 8.8
CVE-2025-55006

Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not a…

Fix: 2.34.0+
Fix from $1,950 2025-08-09
Frappe HIGH 8.8
CVE-2025-52898

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor …

Fix: 14.94.3 / 15.58.0+
Fix from $1,950 2025-06-30
Frappe MEDIUM 5.4
CVE-2025-52896

Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious…

Fix: 14.94.2 / 15.57.0+
Fix from $1,600 2025-06-30
Frappe HIGH 7.5
CVE-2025-52895

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted requ…

Fix: 14.94.3 / 15.58.0+
Fix from $1,950 2025-06-30
Erpnext HIGH 8.1
CVE-2025-28062

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unau…

No fix yet
Fix from $1,950 2025-05-05
Frappe HIGH 7.5
CVE-2025-30217

Frappe is a full-stack web application framework. Prior to versions 14.93.2 and 15.55.0, a SQL Injection vulnerability has been identified in Frappe …

Fix: 14.93.2 / 15.55.0+
Fix from $1,950 2025-03-26
Frappe HIGH 8.8
CVE-2025-30213

Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a spec…

Fix: 14.91.0 / 15.52.0+
Fix from $1,950 2025-03-25
Frappe HIGH 7.5
CVE-2025-30212

Frappe is a full-stack web application framework. An SQL Injection vulnerability has been identified in Frappe Framework prior to versions 14.89.0 an…

Fix: 14.89.0 / 15.51.0+
Fix from $1,950 2025-03-25
Frappe HIGH 7.5
CVE-2025-30214

Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure…

Fix: 14.89.0 / 15.51.0+
Fix from $1,950 2025-03-25
Frappe MEDIUM 6.1
CVE-2024-34074

Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to u…

Fix: 14.74.0 / 15.26.0+
Fix from $1,600 2024-05-14
Frappe MEDIUM 6.5
CVE-2024-27105

Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed using certain endpoints, gra…

Fix: 14.66.3 / 15.16.0+
Fix from $1,600 2024-03-21
Frappe HIGH 7.5
CVE-2024-24813

Frappe is a full-stack web application framework. Prior to versions 14.64.0 and 15.0.0, SQL injection from a particular whitelisted method can result…

Fix: 14.64.0+
Fix from $1,950 2024-03-21
Frappe MEDIUM 5.4
CVE-2024-24812

Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and a tightly integrated client side library. Prior …

Fix: 14.59.0 / 15.5.0+
Fix from $1,600 2024-02-07
Frappe MEDIUM 5.4
CVE-2023-46127EPSS 37%

Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious F…

Fix: 14.49.0+
Fix from $1,600 2023-10-23
Learning MEDIUM 6.1
CVE-2023-5555

Cross-site Scripting (XSS) - Generic in GitHub repository frappe/lms prior to 5614a6203fb7d438be8e2b1e3030e4528d170ec4.

Patch available
Fix from $1,600 2023-10-12