Vulnerability index

Browse CVEs

121 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Learning CRITICAL 9.8
CVE-2023-42807

Frappe LMS is an open source learning management system. In versions 1.0.0 and prior, on the People Page of LMS, there was an SQL Injection vulnerabi…

Fix: after 1.0.0
Fix from $2,300 2023-09-21
Frappe HIGH 7.5
CVE-2023-41328

Frappe is a low code web framework written in Python and Javascript. A SQL Injection vulnerability has been identified in the Frappe Framework which …

Fix: 13.46.1 / 14.20.0+
Fix from $1,950 2023-09-06
Frappe MEDIUM 6.5
CVE-2022-41712

Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correc…

No fix yet
Fix from $1,600 2022-11-25
Frappe MEDIUM 6.1
CVE-2022-3988

A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functionality of the file frappe/templa…

Fix: after 14.14.3
Fix from $1,600 2022-11-14
Erpnext MEDIUM 6.1
CVE-2022-28598

Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is pla…

No fix yet
Fix from $1,600 2022-08-22
Erpnext MEDIUM 5.5
CVE-2022-23055

In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker…

Fix: 13.1.0+
Fix from $1,600 2022-06-22
Erpnext MEDIUM 5.4
CVE-2022-23057

In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low priv…

Fix: 13.1.0+
Fix from $1,600 2022-06-22
Frappe MEDIUM 5.3
CVE-2020-35175

Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

Fix: after 12.12.0
Fix from $1,600 2020-12-11
Frappe HIGH 7.5
CVE-2020-27508

In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security.

Fix: 12.10.0+
Fix from $1,950 2020-12-11
Erpnext HIGH 8.8
CVE-2020-6145

An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause …

No fix yet
Fix from $1,950 2020-08-10
Erpnext MEDIUM 6.1
CVE-2019-20514

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20515

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20516

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20517

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20518

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20519

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20520

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20521

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.

No fix yet
Fix from $1,600 2020-03-19
Frappe HIGH 7.5
CVE-2019-20529

In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (…

Patch available
Fix from $1,950 2020-03-18
Erpnext MEDIUM 6.1
CVE-2019-20511

ERPNext 11.1.47 allows blog?blog_category= Frame Injection.

No fix yet
Fix from $1,600 2020-03-18
Frappe MEDIUM 6.1
CVE-2019-15700

public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "…

Fix: after 12.0.8
Fix from $1,600 2019-08-27
Frappe CRITICAL 9.8
CVE-2019-14965

An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.

Fix: 12.0.4+
Fix from $2,300 2019-08-12
Frappe HIGH 8.8
CVE-2019-14966

An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.

Fix: after 12.0.4
Fix from $1,950 2019-08-12
Frappe MEDIUM 6.1
CVE-2019-14967

An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.

Fix: 11.1.46+
Fix from $1,600 2019-08-12
Erpnext HIGH 7.5
CVE-2018-20061

A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, man…

Fix: 11.0.3+
Fix from $1,950 2018-12-11
Erpnext HIGH 8.8
CVE-2018-3882

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio…

No fix yet
Fix from $1,950 2018-09-12
Erpnext HIGH 8.8
CVE-2018-3883

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio…

No fix yet
Fix from $1,950 2018-09-12
Erpnext HIGH 8.8
CVE-2018-3884

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio…

No fix yet
Fix from $1,950 2018-09-12
Erpnext HIGH 8.8
CVE-2018-3885

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio…

No fix yet
Fix from $1,950 2018-09-12
Erpnext MEDIUM 6.1
CVE-2018-11339

An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.

No fix yet
Fix from $1,600 2018-05-22