Vulnerability index

Browse CVEs

121 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-26031 Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified… Learning 2.44.0+ Fix from $1,6002026-02-11 MEDIUM 6.1 CVE-2026-25956 Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious signup URL for a frappe site whi… Frappe 14.99.14 / 15.94.0+ Fix from $1,6002026-02-10 MEDIUM 5.4 CVE-2025-65923 A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1 when using the Update Existi… Erpnext after 15.88.1 Fix from $1,6002026-02-03 MEDIUM 5.4 CVE-2026-23497 Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and earlier, there is a stored XSS v… Learning 2.45.0+ Fix from $1,6002026-01-14 HIGH 7.5 CVE-2025-68953 Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests that are vulnerable to path … Frappe 14.99.6 / 15.88.1+ Fix from $1,9502026-01-05 CRITICAL 9.0 CVE-2025-68929 Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tri… Frappe 14.99.6 / 15.88.1+ Fix from $2,3002025-12-29 MEDIUM 5.4 CVE-2025-68928 Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could set crafted URLs in a website … Frappe Crm 1.56.2+ Fix from $1,6002025-12-29 CRITICAL 9.6 CVE-2025-67289 An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploadin… Erpnext No fix yet Fix from $2,3002025-12-22 HIGH 8.8 CVE-2025-66437 An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function rend… Erpnext after 15.89.0 Fix from $1,9502025-12-15 HIGH 8.8 CVE-2025-66438 A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, th… Erpnext after 15.89.0 Fix from $1,9502025-12-15 HIGH 8.8 CVE-2025-66439 An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.accounts.doctype.payment_entry.p… Erpnext after 15.89.0 Fix from $1,9502025-12-15 HIGH 8.8 CVE-2025-66440 An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/accounts/doctype/payment_entry/p… Erpnext after 15.89.0 Fix from $1,9502025-12-15 HIGH 8.8 CVE-2025-66434 An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function r… Erpnext after 15.89.0 Fix from $1,9502025-12-15 MEDIUM 5.4 CVE-2025-67734 Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allowed authenticated… Learning 2.42.0+ Fix from $1,6002025-12-12 MEDIUM 5.4 CVE-2025-67730 Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allow authenticated u… Learning 2.42.0+ Fix from $1,6002025-12-12 HIGH 8.8 CVE-2025-10655 SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL state… Helpdesk Patch available Fix from $1,9502025-12-09 MEDIUM 6.5 CVE-2025-66581 Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, a flaw in the server-side aut… Learning 2.41.0+ Fix from $1,6002025-12-05 CRITICAL 9.0 CVE-2025-65267 In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. … Erpnext Mitigation only Fix from $2,3002025-12-03 CRITICAL 9.8 CVE-2025-66205 Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to… Frappe 14.99.2 / 15.86.0+ Fix from $2,3002025-12-01 HIGH 8.6 CVE-2025-66206 Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path traversal attacks, wherein s… Frappe 14.99.2 / 15.86.0+ Fix from $1,9502025-12-01 HIGH 8.8 CVE-2025-11461 Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. Thi… Frappe Crm Patch available Fix from $1,9502025-11-26 MEDIUM 5.4 CVE-2025-64707 Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, when admins rev… Learning 2.41.0+ Fix from $1,6002025-11-12 MEDIUM 5.4 CVE-2025-62779 Frappe Learning is a learning system that helps users structure their content. In Frappe Learning 2.39.1 and earlier, users were able to add HTML thr… Learning 2.39.2+ Fix from $1,6002025-10-27 MEDIUM 5.3 CVE-2025-62778 Frappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to a… Learning 2.39.2+ Fix from $1,6002025-10-27 MEDIUM 6.1 CVE-2025-62407 Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the l… Frappe 14.98.0 / 15.83.0+ Fix from $1,6002025-10-16 MEDIUM 5.3 CVE-2025-62158 Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments upl… Learning Patch available Fix from $1,6002025-10-10 MEDIUM 6.1 CVE-2025-11282 A vulnerability was found in Frappe LMS 2.34.x/2.35.0. The impacted element is an unknown function of the component Incomplete Fix CVE-2025-55006. Pe… Learning after 2.35.0 Fix from $1,6002025-10-05 MEDIUM 5.0 CVE-2025-11281 A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished C… Learning No fix yet Fix from $1,6002025-10-05 MEDIUM 6.5 CVE-2025-56380 Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endp… Erpnext No fix yet Fix from $1,6002025-10-02 MEDIUM 6.5 CVE-2025-56381 ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the orde… Erpnext No fix yet Fix from $1,6002025-10-02