Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2026-46546
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user…
Learning
2.52.0+
CRITICAL 9.9
CVE-2026-44442
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks…
Erpnext
16.9.1+
HIGH 7.5
CVE-2026-44446
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection t…
Erpnext
15.104.3 / 16.14.0+
HIGH 7.5
CVE-2026-44447
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through special…
Erpnext
16.9.0+
MEDIUM 6.5
CVE-2026-44445
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (X…
Erpnext
15.104.3 / 16.12.0+
MEDIUM 6.5
CVE-2026-44448
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper author…
Erpnext
15.102.0 / 16.11.0+
MEDIUM 5.7
CVE-2026-44440
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restric…
Erpnext
15.101.1 / 16.10.0+
CRITICAL 9.8
CVE-2026-38431
ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates ca…
Erpnext
after 15.103.1
MEDIUM 6.1
CVE-2026-38432
ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit …
Erpnext
after 15.103.1
HIGH 8.8
CVE-2023-54345
Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role …
Erpnext
No fix yet
MEDIUM 6.1
CVE-2026-41430
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect para…
Press
0.16.0+
HIGH 7.5
CVE-2026-41317
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).`press.api.acc…
Press
0.9.0+
MEDIUM 5.4
CVE-2026-3837
An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the aff…
Frappe
Patch available
MEDIUM 5.4
CVE-2026-3673
An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where…
Frappe
No fix yet
MEDIUM 6.5
CVE-2026-41320
Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a …
Frappe Hr
14.38.1 / 15.54.0+
MEDIUM 6.5
CVE-2026-40888
Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role…
Frappe Hr
15.58.1 / 16.4.1+
MEDIUM 6.5
CVE-2026-40889
Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthor…
Frappe Hr
15.58.2 / 16.4.2+
CRITICAL 9.1
CVE-2026-31017
A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where us…
Erpnext
Mitigation only
CRITICAL 9.1
CVE-2026-39351
Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.
Frappe
15.104.0 / 16.14.0+
CRITICAL 9.8
CVE-2026-35614
Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_update. This vulnerability is fix…
Frappe
15.104.0 / 16.14.0+
MEDIUM 6.1
CVE-2026-34606
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, …
Learning
2.48.0+
HIGH 7.5
CVE-2026-32954
ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-…
Erpnext
15.100.0 / 16.8.0+
CRITICAL 9.8
CVE-2026-31877
Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result i…
Frappe
14.99.0 / 15.84.0+
MEDIUM 5.4
CVE-2026-31879
Frappe is a full-stack web application framework. Prior to 14.100.2, 15.101.0, and 16.10.0, due to a lack of validation and improper permission check…
Frappe
14.100.2 / 15.101.0+
MEDIUM 5.0
CVE-2026-31878
Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a crafted request to an endpoi…
Frappe
14.100.1 / 15.100.0+
HIGH 8.8
CVE-2026-29081
Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to SQL injection through specia…
Frappe
14.100.1+
HIGH 7.2
CVE-2026-28436
Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted image URL that results in XSS…
Frappe
15.102.0 / 16.11.0+
HIGH 7.1
CVE-2026-29077
Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation when sharing documents, a user …
Frappe
14.100.0 / 15.98.0+
CRITICAL 9.1
CVE-2026-27471
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lack…
Erpnext
15.98.1 / 16.6.1+
MEDIUM 5.3
CVE-2026-26977
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized use…
Learning
2.45.0+