Vulnerability index

Browse CVEs

27 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Erpnext HIGH 8.8
CVE-2023-54345

Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role …

No fix yet
Fix from $1,950 2026-05-05
Frappe MEDIUM 5.4
CVE-2026-3673

An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where…

No fix yet
Fix from $1,600 2026-04-22
Erpnext CRITICAL 9.1
CVE-2026-31017

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where us…

Mitigation only
Fix from $2,300 2026-04-08
Erpnext CRITICAL 9.6
CVE-2025-67289

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploadin…

No fix yet
Fix from $2,300 2025-12-22
Erpnext CRITICAL 9.0
CVE-2025-65267

In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. …

Mitigation only
Fix from $2,300 2025-12-03
Learning MEDIUM 5.0
CVE-2025-11281

A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished C…

No fix yet
Fix from $1,600 2025-10-05
Erpnext MEDIUM 6.5
CVE-2025-56380

Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endp…

No fix yet
Fix from $1,600 2025-10-02
Erpnext MEDIUM 6.5
CVE-2025-56381

ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the orde…

No fix yet
Fix from $1,600 2025-10-02
Erpnext MEDIUM 5.4
CVE-2025-56379

A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or H…

No fix yet
Fix from $1,600 2025-10-02
Erpnext HIGH 8.1
CVE-2025-28062

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unau…

No fix yet
Fix from $1,950 2025-05-05
Frappe MEDIUM 6.5
CVE-2022-41712

Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correc…

No fix yet
Fix from $1,600 2022-11-25
Erpnext MEDIUM 6.1
CVE-2022-28598

Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is pla…

No fix yet
Fix from $1,600 2022-08-22
Erpnext HIGH 8.8
CVE-2020-6145

An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause …

No fix yet
Fix from $1,950 2020-08-10
Erpnext MEDIUM 6.1
CVE-2019-20514

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20515

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20516

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20517

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20518

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20519

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20520

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20521

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.

No fix yet
Fix from $1,600 2020-03-19
Erpnext MEDIUM 6.1
CVE-2019-20511

ERPNext 11.1.47 allows blog?blog_category= Frame Injection.

No fix yet
Fix from $1,600 2020-03-18
Erpnext HIGH 8.8
CVE-2018-3882

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio…

No fix yet
Fix from $1,950 2018-09-12
Erpnext HIGH 8.8
CVE-2018-3883

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio…

No fix yet
Fix from $1,950 2018-09-12
Erpnext HIGH 8.8
CVE-2018-3884

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio…

No fix yet
Fix from $1,950 2018-09-12
Erpnext HIGH 8.8
CVE-2018-3885

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio…

No fix yet
Fix from $1,950 2018-09-12
Erpnext MEDIUM 6.1
CVE-2018-11339

An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.

No fix yet
Fix from $1,600 2018-05-22