Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Frappe

39 known vulnerabilities

7
CRITICAL
8
HIGH
23
MEDIUM

Top Products

erpnext 15 frappe 13 learning 6 frappe hr 3 press 2
38 CVEs
5.4
CVE-2026-46546

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version

5.9
CVE-2026-44448

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints fa

8.8
CVE-2026-44447

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to

8.8
CVE-2026-44446

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were

6.5
CVE-2026-44445

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restrict

9.9
CVE-2026-44442

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforc

5.0
CVE-2026-44441

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user cou

6.5
CVE-2026-44440

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitati

6.1
CVE-2026-38432

ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with

9.8
CVE-2026-38431

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to crea

8.8
CVE-2023-54345

Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated us

6.1
CVE-2026-41430

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-

7.5
CVE-2026-41317

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-

5.4
CVE-2026-3837

An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution wh

5.4
CVE-2026-3673

An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim ope

6.5
CVE-2026-41320

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a special

6.5
CVE-2026-40889

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authentica

6.5
CVE-2026-40888

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authent

4.3
CVE-2026-39415

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0,

9.1
CVE-2026-31017

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frapp

9.1
CVE-2026-39351

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype acce

9.8
CVE-2026-35614

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_upda

6.1
CVE-2026-34606

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27

7.1
CVE-2026-32954

ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpo

5.4
CVE-2026-31879

Frappe is a full-stack web application framework. Prior to 14.100.2, 15.101.0, and 16.10.0, due to a lack of validation

5.0
CVE-2026-31878

Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a

9.8
CVE-2026-31877

Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a ce

6.5
CVE-2026-29081

Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to

7.1
CVE-2026-29077

Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation wh

7.2
CVE-2026-28436

Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted

9.1
CVE-2026-27471

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 1

5.3
CVE-2026-26977

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.

5.3
CVE-2026-26031

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0,

6.1
CVE-2026-25956

Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious sig

4.1
CVE-2025-65924

ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are inte

5.4
CVE-2025-65923

A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1

5.4
CVE-2026-23497

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and ear

7.5
CVE-2025-68953

Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests

Frequently Asked Questions

How many CVEs affect Frappe?

Frappe has 39 CVE records in our database, including 8 critical and 8 high severity vulnerabilities.

What are the most severe Frappe vulnerabilities?

Frappe has 8 critical severity (CVSS 9.0+) and 8 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Frappe vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Frappe products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Frappe Vulnerabilities

CyberStrike scans your infrastructure for Frappe vulnerabilities and provides real-time remediation guidance.

Get Started