Technology · Frappe
Frappe Framework vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 21 vulnerabilities in Frappe Framework: 0 in the last 7 days and 16 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2023-51769, was published on 14 September 2026.
- Last 7 days
- 0
- Last 90 days
- 16
- Critical, all time
- 3
- Exploited in the wild
- 0
About Frappe Framework
Frappe is a full-stack, batteries-included, Python-based web framework designed to build database-driven applications.
Latest Frappe Framework vulnerabilities
- CVE-2023-51769: Frappe cross-site scripting in blog and exception pagesmediumCVSS 6.1EPSS 0.2%
- CVE-2026-81731: Frappe workspace card description XSSmediumCVSS 5.4EPSS 0.3%
- CVE-2026-66003: Frappe access control bypass in REST APIinfoEPSS 0.4%
- CVE-2026-66002: Frappe user enumeration in personal data download requestinfoEPSS 0.8%
- CVE-2026-66001: Frappe OAuth2 authorization bypass via missing CSRF and method restrictionsinfoCVSS 6.5EPSS 0.3%
- CVE-2026-63654: Frappe bulk workflow approval CSRF in workflow endpointinfoEPSS 0.3%
- CVE-2026-62315: Frappe mass assignment vulnerability in set_valueinfoEPSS 0.5%
- CVE-2026-53569: Frappe auth bypass in toggle_like and mark_as_seeninfoEPSS 0.5%
- CVE-2026-49391: Frappe Data Import stored cross-site scripting in column headersinfoEPSS 0.5%
- CVE-2026-47765: Frappe authorization bypass in document restore endpointsinfoEPSS 0.4%
- CVE-2026-47194: Frappe host header poisoning in magic login link generationinfoCVSS 7.1EPSS 0.3%
- CVE-2026-47185: Frappe Workspace Save API broken access controlinfoCVSS 6.5EPSS 0.4%
- CVE-2026-49394: Frappe authorization bypass in Workspace update_page endpointinfoCVSS 7.1
- CVE-2026-42219: Frappe path traversal in download_backupsinfoCVSS 6.9
- CVE-2026-41482: Frappe Framework path traversal in Chrome PDF GeneratorinfoCVSS 7.1
- CVE-2025-30212: PYSEC-2026-1390 - Frappe has possibility of SQL injection due to improper validationsmediumCVSS 4EPSS 0.4%
- CVE-2026-3837: Frappe Framework stored XSS in icon and color fieldsmediumCVSS 5.4
- CVE-2026-3673: Frappe Framework stored XSS in Tag Pill RenderermediumCVSS 5.4
- CVE-2026-31017: Frappe ERPNext and Frappe Framework SSRF in Print Format PDF generationcriticalCVSS 9.1EPSS 0.3%
- CVE-2026-39351: Frappe unrestricted Doctype access via API exploitcriticalCVSS 9.1EPSS 0.3%
- CVE-2025-67289: Frappe Framework and ERPNext Arbitrary File Upload in AttachmentscriticalCVSS 9.6EPSS 0.4%
Most severe Frappe Framework vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-67289: Frappe Framework and ERPNext Arbitrary File Upload in AttachmentscriticalCVSS 9.6EPSS 0.4%
- CVE-2026-39351: Frappe unrestricted Doctype access via API exploitcriticalCVSS 9.1EPSS 0.3%
- CVE-2026-31017: Frappe ERPNext and Frappe Framework SSRF in Print Format PDF generationcriticalCVSS 9.1EPSS 0.3%
- CVE-2023-51769: Frappe cross-site scripting in blog and exception pagesmediumCVSS 6.1EPSS 0.2%
- CVE-2026-81731: Frappe workspace card description XSSmediumCVSS 5.4EPSS 0.3%
- CVE-2026-3837: Frappe Framework stored XSS in icon and color fieldsmediumCVSS 5.4
- CVE-2026-3673: Frappe Framework stored XSS in Tag Pill RenderermediumCVSS 5.4
- CVE-2025-30212: PYSEC-2026-1390 - Frappe has possibility of SQL injection due to improper validationsmediumCVSS 4EPSS 0.4%
- CVE-2026-47194: Frappe host header poisoning in magic login link generationinfoCVSS 7.1EPSS 0.3%
- CVE-2026-49394: Frappe authorization bypass in Workspace update_page endpointinfoCVSS 7.1
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 4 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 4 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 5 | 0 | |
| 24 Aug 2026 | 2 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/frappe.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Frappe Framework vulnerabilities", https://junglewise.ai/threats/technologies/frappe, 26 September 2026.