📦

frappe

Vendor: frappe

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 3 Remote Access
Total CVEs 100 Total Indexed
Avg. EPSS 1.28% Exploit Prob.
Latest CVE CVE-2026-3837 Apr 22

Security Vulnerability Index

Page 5 / 10
5.3 CVSS

Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

EPSS: 0.88%
7.5 CVSS

In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security.

EPSS: 1.33%
7.5 CVSS

In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files.

EPSS: 1.33%
6.1 CVSS

public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.

EPSS: 0.88%
6.1 CVSS

An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.

EPSS: 1.23%
8.8 CVSS

An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.

EPSS: 1.68%
9.8 CVSS

An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.

EPSS: 2.57%
8.8 CVSS

[ERPNext][Frappe Version <= 7.1.27] SQL injection vulnerability in frappe.share.get_users allows remote authenticated users to execute arbitrary SQL commands via the fields parameter.

EPSS: 1.12%