Technology · Frappe
Frappe ERPNext vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 17 vulnerabilities in Frappe ERPNext: 2 in the last 7 days and 5 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-96672, was published on 23 September 2026.
- Last 7 days
- 2
- Last 90 days
- 5
- Critical, all time
- 4
- Exploited in the wild
- 0
About Frappe ERPNext
ERPNext is an open-source enterprise resource planning (ERP) software built on the Frappe framework.
Latest Frappe ERPNext vulnerabilities
- CVE-2026-96672: Frappe ERPNext arbitrary method invocation in Financial Report TemplatemediumCVSS 6.4EPSS 0.2%
- CVE-2026-94113: Frappe ERPNext authorization bypass in timesheet endpointsmediumCVSS 6.5EPSS 0.4%
- CVE-2026-13227: ERPNext improper authorization in Prospect opportunities APIinfoEPSS 0.4%
- CVE-2026-12895: Frappe ERPNext SQL injection in Supplier recordsinfoCVSS 7.1
- CVE-2026-55242: Frappe ERPNext server-side template injection in configuration fieldshighCVSS 8.8
- CVE-2026-42840: Frappe ERPNext stored XSS in POS customer fieldsinfoCVSS 5.1
- CVE-2026-42839: Frappe ERPNext stored XSS in POS cart interfaceinfoCVSS 4.8
- CVE-2026-44448: Frappe ERPNext missing authorization in document endpointsmediumCVSS 5.9
- CVE-2026-44446: Frappe ERPNext SQL injection in multiple endpointshighCVSS 8.8
- CVE-2026-44445: Frappe ERPNext XXE in EDI ModuleinfoCVSS 5.3
- CVE-2026-44442: Frappe ERPNext missing authorization in document modification endpointscriticalCVSS 9.9
- CVE-2026-44441: Frappe ERPNext SSRF in web endpointmediumCVSS 5
- CVE-2026-44440: Frappe ERPNext path traversal in file endpointmediumCVSS 6.5
- CVE-2026-38432: Frappe ERPNext stored XSS in Email Template enginemediumCVSS 6.1EPSS 0.2%
- CVE-2026-38431: Frappe ERPNext SSTI in Email Template EnginecriticalCVSS 9.8EPSS 0.4%
- CVE-2026-31017: Frappe ERPNext and Frappe Framework SSRF in Print Format PDF generationcriticalCVSS 9.1EPSS 0.3%
- CVE-2025-67289: Frappe Framework and ERPNext Arbitrary File Upload in AttachmentscriticalCVSS 9.6EPSS 0.4%
Most severe Frappe ERPNext vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-44442: Frappe ERPNext missing authorization in document modification endpointscriticalCVSS 9.9
- CVE-2026-38431: Frappe ERPNext SSTI in Email Template EnginecriticalCVSS 9.8EPSS 0.4%
- CVE-2025-67289: Frappe Framework and ERPNext Arbitrary File Upload in AttachmentscriticalCVSS 9.6EPSS 0.4%
- CVE-2026-31017: Frappe ERPNext and Frappe Framework SSRF in Print Format PDF generationcriticalCVSS 9.1EPSS 0.3%
- CVE-2026-55242: Frappe ERPNext server-side template injection in configuration fieldshighCVSS 8.8
- CVE-2026-44446: Frappe ERPNext SQL injection in multiple endpointshighCVSS 8.8
- CVE-2026-94113: Frappe ERPNext authorization bypass in timesheet endpointsmediumCVSS 6.5EPSS 0.4%
- CVE-2026-44440: Frappe ERPNext path traversal in file endpointmediumCVSS 6.5
- CVE-2026-96672: Frappe ERPNext arbitrary method invocation in Financial Report TemplatemediumCVSS 6.4EPSS 0.2%
- CVE-2026-38432: Frappe ERPNext stored XSS in Email Template enginemediumCVSS 6.1EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 1 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/erpnext.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Frappe ERPNext vulnerabilities", https://junglewise.ai/threats/technologies/erpnext, 26 September 2026.