Frappe Erpnext
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Frappe Erpnext.
By the Year
In 2026 there have been 27 vulnerabilities in Frappe Erpnext with an average score of 7.5 out of ten. Last year, in 2025 Erpnext had 17 security vulnerabilities published. That is, 10 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.15
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 27 | 7.47 |
| 2025 | 17 | 7.62 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 5 | 5.40 |
| 2021 | 0 | 0.00 |
| 2020 | 10 | 0.00 |
| 2019 | 0 | 0.00 |
| 2018 | 2 | 0.00 |
It may take a day or so for new Erpnext vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Frappe Erpnext Security Vulnerabilities
Frappe ERPNext <15.121.0/16.34.0> timesheet info disclosure
CVE-2026-94113
7.1 - High
- September 20, 2026
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to enumerate and retrieve billable time logs including project names, billing amounts, and work descriptions without proper authorization checks.
AuthZ
ERPNext <15.116.0/16.23.0 SQL Injection via Unvalidated Doctype Filter
CVE-2026-65822
7.6 - High
- August 17, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates it into raw SQL in get_sales_details and get_last_sales_amt, allowing an authenticated user to extract sensitive information and manipulate database queries. This issue is fixed in versions 15.116.0 and 16.23.0.
SQL Injection
ERPNext 15.x/16.x RCE via frappe.render_template
CVE-2026-65974
9.9 - Critical
- August 17, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restrict_globals, allowing server-side template injection and remote code execution. This issue is fixed in versions 15.111.0 and 16.22.0.
1336
ERPNext <15.118.0/16.29.0: RCE via unrestricted template rendering
CVE-2026-72911
9.9 - Critical
- August 10, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render subject, body, and pdf_name fields with unrestricted globals including frappe.utils, allowing an authenticated user with a common operational role to inject template expressions, execute arbitrary server-side code, and read data across the application. This issue is fixed in versions 15.118.0 and 16.29.0.
1336
ERPNext <15.112/16.22 Write-Perm Omission in Account Functions
CVE-2026-72910
7.1 - High
- August 10, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions across erpnext/accounts/doctype/account/account.py, erpnext/accounts/doctype/process_payment_reconciliation/process_payment_reconciliation.py, erpnext/accounts/doctype/purchase_invoice/purchase_invoice.py, and erpnext/accounts/utils.py omit required write permission checks, allowing authenticated limited users to modify protected data beyond their roles. This issue is fixed in versions 15.112.0 and 16.22.0.
AuthZ
ERPNext <=15.112.0/<=16.23.0: Authenticated Data Leakage ReceivablePayableReport
CVE-2026-72909
7.1 - High
- August 10, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not apply Customer and Supplier user permissions to the Payment Ledger Entry dynamic-link party field, allowing any authenticated user to read unauthorized cross-company financial data in Accounts Receivable and Accounts Payable reports. This issue is fixed in versions 15.112.0 and 16.23.0.
Authorization
ERPNext 15/16 SQLi in get_tax_template (v15.109/V16.20)
CVE-2026-72908
6.5 - Medium
- August 10, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WHERE clause from request-influenced posting_date and args values, allowing an authenticated low-privilege user to inject SQL and extract sensitive information. This issue is fixed in versions 15.109.0 and 16.20.0.
SQL Injection
ERPNext 15/16 add_ac Permission Bypass via ignore_permissions
CVE-2026-72907
6.5 - Medium
- August 10, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without enforcing Account create permission, allowing an authenticated limited user to create unauthorized accounting master records and affect financial data integrity and audit trails. This issue is fixed in versions 15.111.0 and 16.22.0.
AuthZ
ERPNext 15.111/16.22 process_statement_of_accounts perm bypass
CVE-2026-72906
4.3 - Medium
- August 10, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py lacks a Process Statement Of Accounts permission check, allowing an authenticated low-privilege user to trigger automated emails outside the permitted role. This issue is fixed in versions 15.111.0 and 16.22.0.
AuthZ
ERPNext Improper Authorization in Prospect.get_opportunities API <15.115 & <16.26
CVE-2026-13227
7.1 - High
- August 04, 2026
An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects ERPNext: before 15.115.0, before 16.26.0.
AuthZ
SQLi in ERPNext 15.107.0 via str.format() Auth Low Priv Exec SQL
CVE-2026-12895
- July 29, 2026
SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing parameterized queries, allowing the name (docname) of a Supplier record containing SQL metacharacters to be interpreted as part of the query. Exploitation of this vulnerability could allow an authenticated user with low privileges to execute arbitrary SQL queries, bypass Frappes access restrictions (DocPerm), extract confidential information from the databaseincluding fragments of the administrators password hashand access other sensitive data, such as credentials, integration tokens, or financial information.
SQL Injection
ERPNext SSTI via Config Field <15.111.0 and <16.22.0
CVE-2026-55242
8.8 - High
- July 15, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data outside the user's normal permission scope. This issue is fixed in versions 15.111.0 and 16.22.0.
AuthZ
ERPNext 16.16.0 XSS via Item fields in POS cart
CVE-2026-42839
- June 03, 2026
An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, description, or image fields of an Item and trigger unescaped rendering in the Point of Sale (POS) cart interface for every operator who adds that item to a transaction.This issue affects ERPNext: 16.16.0.
XSS
ERPNext 16.16 Stored XSS via email_id/mobile_no in POS
CVE-2026-42840
- June 03, 2026
An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of Sale (POS) interface for every operator who selects that customer. This issue affects ERPNext: 16.16.0.
XSS
ERPNext <15.102.0/16.11.0: Auth Bypass on Endpoint
CVE-2026-44448
5.9 - Medium
- May 13, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 15.102.0 and 16.11.0.
AuthZ
ERPNext <16.9.0 SQLi in Endpoints
CVE-2026-44447
8.8 - High
- May 13, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 16.9.0.
SQL Injection
SQLi in ERPNext <15.104.3 / <16.14.0 via endpoints
CVE-2026-44446
8.8 - High
- May 13, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 15.104.3 and 16.14.0.
SQL Injection
ERPNext EDI Mod XXE File Read Vulnerability (15.104.3, 16.12.0)
CVE-2026-44445
- May 13, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enables an authenticated attacker to read files from the local file system, including sensitive configuration files. This vulnerability is fixed in 15.104.3 and 16.12.0.
XXE
ERPNext pre-15.106.0/16.16.0 Remote Service Call via Crafted Request
CVE-2026-44441
5 - Medium
- May 13, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in 15.106.0 and 16.16.0.
SSRF
ERPNext Path Traversal < 15.101.1 / 16.10.0
CVE-2026-44440
6.5 - Medium
- May 13, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on an endpoint allows an authenticated adjacent attacker to read arbitrary files. This vulnerability is fixed in 15.101.1 and 16.10.0.
Directory traversal
ERPNext Pre-16.9.1 Auth Bypass Endpoints
CVE-2026-44442
9.9 - Critical
- May 13, 2026
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 16.9.1.
AuthZ
ERPNext SSTI in Email Templates before v15.103.1
CVE-2026-38431
9.8 - Critical
- May 05, 2026
ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.
Code Injection
ERPNext <15.103.1 XSS in Email Template Engine
CVE-2026-38432
6.1 - Medium
- May 05, 2026
ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when the template is applied.
XSS
SSRF via PDF Render in ERPNext 16.0.1 Print Format
CVE-2026-31017
9.1 - Critical
- April 08, 2026
A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When generating PDFs from user-controlled HTML content, the application allows the inclusion of HTML elements such as <iframe> that reference external resources. The PDF rendering engine automatically fetches these resources on the server side. An attacker can abuse this behavior to force the server to make arbitrary HTTP requests to internal services, including cloud metadata endpoints, potentially leading to sensitive information disclosure.
SSRF
ERP <16.8.0/15.100.0: Time/Boolean Blind SQLi via API Endpoints
CVE-2026-32954
7.1 - High
- March 20, 2026
ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-based and boolean-based blind SQL injection due to insufficient parameter validation, allowing attackers to infer database information. This issue has been fixed in versions 15.100.0 and 16.8.0.
SQL Injection
Unauthorized Document Access in ERPNext <=15.98.0,16.0.0-rc.1&<=16.6.0 (CVE-2026-27471)
CVE-2026-27471
- February 21, 2026
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.
AuthZ
ERPNext 15.88.1 CSV Import Stored XSS via Update Existing Records
CVE-2025-65923
5.4 - Medium
- February 03, 2026
A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1 when using the Update Existing Recordsoption. An attacker can embed malicious JavaScript code into a CSV field, which is then stored in the database and executed whenever the affected record is viewed by a user within the ERPNext web interface. This exposure may allow an attacker to compromise user sessions or perform unauthorized actions under the context of a victim's account.
XSS
ERPNext v15.89.0 - SQLi via get_outstanding_reference_documents() in payment_entry.py
CVE-2025-66439
9.8 - Critical
- December 15, 2025
An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.accounts.doctype.payment_entry.payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from the database by injecting SQL payloads via the from_posting_date parameter, which is directly interpolated into the query without proper sanitization or parameter binding.
SQL Injection
SSTI in Frappe ERPNext <=15.89.0 via Jinja Terms injection
CVE-2025-66436
4.3 - Medium
- December 15, 2025
An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (terms) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a custom SandboxedEnvironment, several dangerous globals such as frappe.db.sql are still available in the execution context via get_safe_globals(). An authenticated attacker with access to create or modify a Terms and Conditions document can inject arbitrary Jinja expressions into the terms field, resulting in server-side code execution within a restricted but still unsafe context. This vulnerability can be used to leak database information.
1336
ERPNext 15.89.0: SSTI via get_address_display (Jinja Sandbox Bypass)
CVE-2025-66437
8.8 - High
- December 15, 2025
An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders address templates using frappe.render_template() with a context derived from the address_dict parameter, which can be either a dictionary or a string referencing an Address document. Although ERPNext uses a custom Jinja2 SandboxedEnvironment, dangerous functions like frappe.db.sql remain accessible via get_safe_globals(). An authenticated attacker with permission to create or modify an Address Template can inject arbitrary Jinja expressions into the template field. By creating an Address document with a matching country, and then calling the get_address_display API with address_dict="address_name", the system will render the malicious template using attacker-controlled data. This leads to server-side code execution or database information disclosure.
1336
SSTI in Frappe ERPNext 15.89.0 Print Format Rendering
CVE-2025-66438
9.8 - Critical
- December 15, 2025
A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, the API frappe.www.printview.get_html_and_style() triggers the rendering of the html field inside a Print Format document using frappe.render_template(template, doc) via the get_rendered_template() call chain. Although ERPNext wraps Jinja2 in a SandboxedEnvironment, it exposes sensitive functions such as frappe.db.sql through get_safe_globals(). An authenticated attacker with permission to create or modify a Print Format can inject arbitrary Jinja expressions into the html field. Once the malicious Print Format is saved, the attacker can call get_html_and_style() with a target document (e.g., Supplier or Sales Invoice) to trigger the render process. This leads to information disclosure from the database, such as database version, schema details, or sensitive values, depending on the injected payload. Exploitation flow: Create a Print Format with SSTI payload in the html field; call the get_html_and_style() API; triggers frappe.render_template(template, doc) inside get_rendered_template(); leaks database information via frappe.db.sql or other exposed globals.
1336
SQLi in Frappe ERPNext 15.89.0 via to_posting_date
CVE-2025-66440
9.8 - Critical
- December 15, 2025
An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/accounts/doctype/payment_entry/payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from the database by injecting SQL payloads via the to_posting_date parameter, which is directly interpolated into the query without proper sanitization or parameter binding.
SQL Injection
SSTI in Frappe ERPNext (15.89.0) get_dunning_letter_text allows code exec
CVE-2025-66434
8.8 - High
- December 15, 2025
An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (body_text) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a custom SandboxedEnvironment, several dangerous globals such as frappe.db.sql are still available in the execution context via get_safe_globals(). An authenticated attacker with access to configure Dunning Type and its child table Dunning Letter Text can inject arbitrary Jinja expressions, resulting in server-side code execution within a restricted but still unsafe context. This can leak database information.
1336
SSTI in Frappe ERPNext 15.89.0 get_contract_template: Authenticated RCE
CVE-2025-66435
4.3 - Medium
- December 15, 2025
An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (contract_terms) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a custom SandboxedEnvironment, several dangerous globals such as frappe.db.sql are still available in the execution context via get_safe_globals(). An authenticated attacker with access to create or modify a Contract Template can inject arbitrary Jinja expressions into the contract_terms field, resulting in server-side code execution within a restricted but still unsafe context. This vulnerability can be used to leak database information.
1336
SQLi in Frappe ERPNext 15.57.5 get_material_requests_based_on_supplier()
CVE-2025-52039
8.2 - High
- October 01, 2025
In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_request/material_request.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the txt parameter.
SQL Injection
SQL Injection in Frappe ERPNext 15.57.5 get_blanket_orders()
CVE-2025-52040
8.2 - High
- October 01, 2025
In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker can extract all information from databases by injecting a SQL query into the blanket_order_type parameter.
SQL Injection
SQL Injection in Frappe ERPNext 15.57.5 stock_reconciliation get_stock_balance_for
CVE-2025-52041
8.2 - High
- October 01, 2025
In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reconciliation.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the inventory_dimensions_dict parameter.
SQL Injection
SQLi in ERPNext 15.57.5 get_rfq_containing_supplier()
CVE-2025-52042
8.2 - High
- October 01, 2025
In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/request_for_quotation/request_for_quotation.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query via the txt parameter.
SQL Injection
SQL Injection in ERPNext v15.57.5 Chart of Accounts Importer
CVE-2025-52043
6.5 - Medium
- September 30, 2025
In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_accounts_importer.py is vulnerable to SQL injection, which allows an attacker to extract all information from databases by injecting a SQL query into the company parameter.
SQL Injection
SQLi in Frappe ERPNext 15.57.5 loyalty_program.get_details
CVE-2025-52050
6.5 - Medium
- September 30, 2025
In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_program/loyalty_program.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the expiry_date parameter.
SQL Injection
SQLi in Frappe ErpNext v15.57.5 get_timesheet_detail_rate() Timelog
CVE-2025-52049
6.5 - Medium
- September 30, 2025
In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query into the timelog parameter.
SQL Injection
SQLi in Frappe ErpNext v15.57.5 get_income_account() Filters.disabled
CVE-2025-52047
6.5 - Medium
- September 30, 2025
In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the filters.disabled parameter.
SQL Injection
SQL Injection in ERPNext 15.57.5 get_stock_balance()
CVE-2025-52044
7.5 - High
- September 16, 2025
In Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query into inventory_dimensions_dict parameter.
SQL Injection
CSRF in ERPNext 14.82.1: User Deletion & Privilege Escalation
CVE-2025-28062
- May 05, 2025
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.
XSS in ERPNext 12.29.0 from improper input neutralization
CVE-2022-28598
- August 22, 2022
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality
CVE-2022-23055
5.4 - Medium
- June 22, 2022
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.
AuthZ
In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly
CVE-2022-23057
5.4 - Medium
- June 22, 2022
In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.
XSS
In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which
CVE-2022-23056
5.4 - Medium
- June 22, 2022
In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.
XSS
ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability
CVE-2022-23058
5.4 - Medium
- June 22, 2022
ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the username field in my settings which can lead to full account takeover.
XSS
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38
CVE-2020-6145
- August 10, 2020
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
SQL Injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Frappe Erpnext or by Frappe? Click the Watch button to subscribe.