Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
74 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.39% | — | Frappe Erpnext | 16/9/2025 | 17/6/2026 | In Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query into inventory_dimensions_dict parameter. | |
| Analizada | Crítica (9.1) | 0.32% | — | Frappe Erpnext | 6/9/2025 | 17/6/2026 | ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left certain endpoints vulnerable to error-based SQL Injection. Some information like version could be retrieved. This issue is fixed in versions 14.89.2 and 15.76.0. | |
| Analizada | Alta (8.1) | 0.80% | 💥 Exploit | Frappe Erpnext | 5/5/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections. | |
| Modificada | Media (6.1) | 4.1% | 💥 Exploit | Frappe Erpnext | 22/8/2022 | 9/7/2026 | Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. | |
| Modificada | Media (5.5) | 1.2% | — | Frappe Erpnext | 22/6/2022 | 17/6/2026 | In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups… | |
| Modificada | Baja (3.5) | 0.85% | — | Frappe Erpnext | 22/6/2022 | 17/6/2026 | ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover. | |
| Modificada | Media (5.4) | 0.62% | — | Frappe Erpnext | 22/6/2022 | 17/6/2026 | In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile. | |
| Modificada | Baja (3.5) | 0.85% | — | Frappe Erpnext | 22/6/2022 | 17/6/2026 | In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack. | |
| Modificada | Alta (8.8) | 1.8% | — | Frappe Erpnext | 10/8/2020 | 17/6/2026 | An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Media (6.1) | 0.79% | — | Frappe Erpnext | 19/3/2020 | 17/6/2026 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI. | |
| Modificada | Media (6.1) | 0.79% | — | Frappe Erpnext | 19/3/2020 | 17/6/2026 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI. | |
| Modificada | Media (6.1) | 0.79% | — | Frappe Erpnext | 19/3/2020 | 17/6/2026 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address. | |
| Modificada | Media (6.1) | 0.79% | — | Frappe Erpnext | 19/3/2020 | 17/6/2026 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI. | |
| Modificada | Media (6.1) | 0.79% | — | Frappe Erpnext | 19/3/2020 | 17/6/2026 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI. | |
| Modificada | Media (6.1) | 0.79% | — | Frappe Erpnext | 19/3/2020 | 17/6/2026 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI. | |
| Modificada | Media (6.1) | 0.79% | — | Frappe Erpnext | 19/3/2020 | 17/6/2026 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI. | |
| Modificada | Media (6.1) | 0.79% | — | Frappe Erpnext | 19/3/2020 | 17/6/2026 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI. | |
| Modificada | Media (6.1) | 0.68% | — | Frappe Erpnext | 18/3/2020 | 17/6/2026 | ERPNext 11.1.47 allows blog?blog_category= Frame Injection. | |
| Modificada | Alta (7.5) | 1.4% | — | Frappe Erpnext | 11/12/2018 | 17/6/2026 | A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, many ERPNext sites allow account creation via the web. No special privileges are needed to conduct the attack. By calling a JavaScript function that calls a server-side… | |
| Modificada | Alta (8.8) | 0.94% | — | Frappe Erpnext | 12/9/2018 | 17/6/2026 | An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The order_by parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities,… | |
| Modificada | Alta (8.8) | 0.94% | — | Frappe Erpnext | 12/9/2018 | 17/6/2026 | An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these… | |
| Modificada | Alta (8.8) | 0.94% | — | Frappe Erpnext | 12/9/2018 | 17/6/2026 | An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The employee and sort_order parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these… | |
| Modificada | Alta (8.8) | 0.94% | — | Frappe Erpnext | 12/9/2018 | 17/6/2026 | An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The searchfield parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities,… | |
| Modificada | Media (6.1) | 3.8% | 💥 Exploit | Frappe Erpnext | 22/5/2018 | 17/6/2026 | An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment. |