Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
208 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.48% | — | FrappeAI | 7/8/2026 | 8/9/2026 | Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0. | |
| Aplazada | Media (5.1) | 0.47% | — | FrappeAI | 6/8/2026 | 8/9/2026 | Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering previews and results, allowing an authenticated importer to persist script content that executes when another user views the import interface. This issue is fixed in… | |
| Aplazada | Alta (7.1) | 0.45% | — | FrappeAI | 6/8/2026 | 8/9/2026 | Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, allowing an authenticated user to restore deleted documents without the required authorization. This issue is fixed in versions 15.110.0 and… | |
| Aplazada | Alta (8.6) | 0.26% | — | FrappeAI | 6/8/2026 | 8/9/2026 | Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled request Host header, allowing a remote attacker to cause emailed login links to point to an attacker-controlled domain and capture the login token when a recipient… | |
| Aplazada | Media (5.1) | 0.41% | — | FrappeAI | 6/8/2026 | 8/9/2026 | Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing workspace ownership, allowing modification of another user's private workspace and persistent script injection. This issue is fixed in… | |
| Aplazada | Alta (7.1) | 0.43% | — | Frappe ErpnextAI | 4/8/2026 | 28/8/2026 | An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects ERPNext: before 15.115.0, before 16.26.0. | |
| Aplazada | Alta (7.1) | 0.37% | — | FrappeAIFrappe ErpnextAI | 29/7/2026 | 30/7/2026 | SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing parameterized queries, allowing the name (docname) of a Supplier record containing SQL metacharacters to be interpreted as… | |
| Aplazada | Alta (7.1) | 0.37% | — | Frappe LMSAI | 20/7/2026 | 22/7/2026 | Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course. | |
| Aplazada | Alta (8.8) | 0.20% | — | Frappe ErpnextAI | 15/7/2026 | 15/7/2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data outside the user's normal permission scope.… | |
| Aplazada | Media (6.9) | 0.59% | — | FrappeAI | 10/7/2026 | 13/7/2026 | Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0. | |
| Aplazada | Alta (8.6) | 0.68% | — | FrappeAI | 10/7/2026 | 13/7/2026 | Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tarfile members were not sufficiently checked before extraction. This issue is fixed in versions 16.23.0 and 15.112.0. | |
| Aplazada | Alta (7.1) | 0.54% | — | FrappeAI | 10/7/2026 | 13/7/2026 | Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed in version 16.19.0. | |
| Aplazada | Media (5.3) | 0.61% | — | FrappeAI | 10/7/2026 | 14/7/2026 | Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints such as add_attachments. This issue is fixed in versions 16.20.0 and 15.110.0. | |
| Aplazada | Media (5.3) | 0.38% | — | FrappeAI | 10/7/2026 | 14/7/2026 | Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2. | |
| Aplazada | Baja (2.3) | 0.55% | — | FrappeAI | 10/7/2026 | 13/7/2026 | Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT INTO OUTFILE queries, which could potentially work on self-hosted sites if database permissions are not well aligned and MySQL FILE privileges are available. This issue is fixed in versions 16.18.3… | |
| Aplazada | Media (6.9) | 0.68% | — | FrappeAI | 10/7/2026 | 13/7/2026 | Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was possible due to lack of hardening. This issue is fixed in versions 16.19.0 and 15.109.0. | |
| Aplazada | Alta (7.1) | 0.50% | — | FrappeAIGoogle ChromeAI | 10/7/2026 | 13/7/2026 | Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion were possible through secure local resource access in the Chrome PDF Generator. This issue is fixed in version 16.18.3. | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component. | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel. | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer. | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer. |