Frappe
Frappe Erpnext: vulnerabilidades y CVE
Frappe Erpnext tiene 74 vulnerabilidades publicadas, 39 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE74
Últimos 12 meses39
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-96672 | Media (5.3) | 0.22% | — | 23 sept 2026 | Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply… |
| CVE-2026-94113 | Alta (7.1) | 0.42% | — | 20 sept 2026 | Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can… |
| CVE-2026-65974 | Crítica (9.9) | 1.0% | — | 17 ago 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is… |
| CVE-2026-65822 | Alta (7.6) | 0.46% | — | 17 ago 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates… |
| CVE-2026-72911 | Crítica (9.9) | 0.72% | — | 10 ago 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in… |
| CVE-2026-72910 | Alta (7.1) | 0.50% | — | 10 ago 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions across… |
| CVE-2026-72909 | Alta (7.1) | 0.47% | — | 10 ago 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in… |
| CVE-2026-72908 | Media (6.5) | 0.51% | — | 10 ago 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WHERE clause from… |
| CVE-2026-72907 | Media (6.5) | 0.44% | — | 10 ago 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without enforcing Account… |
| CVE-2026-72906 | Media (4.3) | 0.35% | — | 10 ago 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py… |
| CVE-2026-13227 | Alta (7.1) | 0.43% | — | 4 ago 2026 | An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This… |
| CVE-2026-12895 | Alta (7.1) | 0.37% | — | 29 jul 2026 | SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing parameterized queries,… |
| CVE-2026-55242 | Alta (8.8) | 0.20% | — | 15 jul 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a… |
| CVE-2026-42840 | Media (5.1) | 0.41% | — | 3 jun 2026 | An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of Sale (POS) interface for every operator who selects… |
| CVE-2026-42839 | Media (4.8) | 0.44% | — | 3 jun 2026 | An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, description, or image fields of an Item and trigger unescaped rendering in the Point of Sale (POS)… |
| CVE-2026-44448 | Media (6.5) | 0.25% | — | 13 may 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted… |
| CVE-2026-44447 | Alta (7.5) | 0.53% | — | 13 may 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract… |
| CVE-2026-44446 | Alta (7.5) | 0.45% | — | 13 may 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor… |
| CVE-2026-44445 | Media (5.3) | 0.38% | — | 13 may 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enables an authenticated… |
| CVE-2026-44442 | Crítica (9.9) | 0.42% | — | 13 may 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This… |
| CVE-2026-44441 | Media (4.3) | 0.27% | — | 13 may 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making an HTTP call to a… |
| CVE-2026-44440 | Media (5.7) | 0.60% | — | 13 may 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on an endpoint allows… |
| CVE-2026-38432 | Media (6.1) | 0.26% | — | 5 may 2026 | ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed… |
| CVE-2026-38431 | Crítica (9.8) | 0.60% | — | 5 may 2026 | ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the… |
| CVE-2023-54345 | Alta (8.7) | 0.61% | — | 5 may 2026 | Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role to execute arbitrary code by exploiting frame introspection. Attackers… |
| CVE-2026-31017 | Crítica (9.1) | 0.42% | — | 8 abr 2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered… |
| CVE-2026-32954 | Alta (7.5) | 0.41% | — | 20 mar 2026 | ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-based and boolean-based blind SQL injection due to insufficient… |
| CVE-2026-27471 | Crítica (9.3) | 0.44% | — | 21 feb 2026 | ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access.… |
| CVE-2025-65924 | Media (4.1) | 0.26% | — | 3 feb 2026 | ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are intended for plain text. Although JavaScript is blocked (preventing XSS), the HTML is still preserved… |
| CVE-2025-65923 | Media (5.4) | 0.19% | — | 3 feb 2026 | A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1 when using the Update Existing Recordsoption. An attacker can embed malicious JavaScript code into… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.