« Volver al listado

Frappe

Frappe Erpnext: vulnerabilidades y CVE

Frappe Erpnext tiene 74 vulnerabilidades publicadas, 39 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE74
Últimos 12 meses39
Críticas9
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-96672Media (5.3)0.22%—23 sept 2026
Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply…
CVE-2026-94113Alta (7.1)0.42%—20 sept 2026
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can…
CVE-2026-65974Crítica (9.9)1.0%—17 ago 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is…
CVE-2026-65822Alta (7.6)0.46%—17 ago 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates…
CVE-2026-72911Crítica (9.9)0.72%—10 ago 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in…
CVE-2026-72910Alta (7.1)0.50%—10 ago 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions across…
CVE-2026-72909Alta (7.1)0.47%—10 ago 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in…
CVE-2026-72908Media (6.5)0.51%—10 ago 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WHERE clause from…
CVE-2026-72907Media (6.5)0.44%—10 ago 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without enforcing Account…
CVE-2026-72906Media (4.3)0.35%—10 ago 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py…
CVE-2026-13227Alta (7.1)0.43%—4 ago 2026
An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This…
CVE-2026-12895Alta (7.1)0.37%—29 jul 2026
SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing parameterized queries,…
CVE-2026-55242Alta (8.8)0.20%—15 jul 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a…
CVE-2026-42840Media (5.1)0.41%—3 jun 2026
An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of Sale (POS) interface for every operator who selects…
CVE-2026-42839Media (4.8)0.44%—3 jun 2026
An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, description, or image fields of an Item and trigger unescaped rendering in the Point of Sale (POS)…
CVE-2026-44448Media (6.5)0.25%—13 may 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted…
CVE-2026-44447Alta (7.5)0.53%—13 may 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract…
CVE-2026-44446Alta (7.5)0.45%—13 may 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor…
CVE-2026-44445Media (5.3)0.38%—13 may 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enables an authenticated…
CVE-2026-44442Crítica (9.9)0.42%—13 may 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This…
CVE-2026-44441Media (4.3)0.27%—13 may 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making an HTTP call to a…
CVE-2026-44440Media (5.7)0.60%—13 may 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on an endpoint allows…
CVE-2026-38432Media (6.1)0.26%—5 may 2026
ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed…
CVE-2026-38431Crítica (9.8)0.60%—5 may 2026
ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the…
CVE-2023-54345Alta (8.7)0.61%—5 may 2026
Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role to execute arbitrary code by exploiting frame introspection. Attackers…
CVE-2026-31017Crítica (9.1)0.42%—8 abr 2026
A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered…
CVE-2026-32954Alta (7.5)0.41%—20 mar 2026
ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-based and boolean-based blind SQL injection due to insufficient…
CVE-2026-27471Crítica (9.3)0.44%—21 feb 2026
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access.…
CVE-2025-65924Media (4.1)0.26%—3 feb 2026
ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are intended for plain text. Although JavaScript is blocked (preventing XSS), the HTML is still preserved…
CVE-2025-65923Media (5.4)0.19%—3 feb 2026
A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1 when using the Update Existing Recordsoption. An attacker can embed malicious JavaScript code into…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services16
  2. T1005 Data from Local System15
  3. T1190 Exploit Public-Facing Application12
  4. T1059 Command and Scripting Interpreter9
  5. T1078 Valid Accounts5
  6. T1189 Drive-by Compromise2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Frappe