Vendor
Frappe vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 43 vulnerabilities in Frappe: 2 in the last 7 days and 23 in the last 90 days, 5 of them critical and 0 exploited in the wild. The most recent, CVE-2026-96672, was published on 23 September 2026. 3 technologies have a page of their own.
- Last 7 days
- 2
- Last 90 days
- 23
- Critical, all time
- 5
- Exploited in the wild
- 0
About Frappe
An open-source software company that develops the Frappe Framework and ERPNext.
Frappe technologies
Latest Frappe vulnerabilities
- CVE-2026-96672: Frappe ERPNext arbitrary method invocation in Financial Report TemplatemediumCVSS 6.4EPSS 0.2%
- CVE-2026-94113: Frappe ERPNext authorization bypass in timesheet endpointsmediumCVSS 6.5EPSS 0.4%
- CVE-2026-54343: Frappe Learning Management System path traversal in SCORM rendererinfoEPSS 0.7%
- CVE-2026-54524: Frappe HR SQL injection in Salary Payments report filtersinfoEPSS 0.5%
- CVE-2023-51769: Frappe cross-site scripting in blog and exception pagesmediumCVSS 6.1EPSS 0.2%
- CVE-2026-81731: Frappe workspace card description XSSmediumCVSS 5.4EPSS 0.3%
- CVE-2026-66003: Frappe access control bypass in REST APIinfoEPSS 0.4%
- CVE-2026-66002: Frappe user enumeration in personal data download requestinfoEPSS 0.8%
- CVE-2026-66001: Frappe OAuth2 authorization bypass via missing CSRF and method restrictionsinfoCVSS 6.5EPSS 0.3%
- CVE-2026-63654: Frappe bulk workflow approval CSRF in workflow endpointinfoEPSS 0.3%
- CVE-2026-62315: Frappe mass assignment vulnerability in set_valueinfoEPSS 0.5%
- CVE-2026-53569: Frappe auth bypass in toggle_like and mark_as_seeninfoEPSS 0.5%
- CVE-2026-49391: Frappe Data Import stored cross-site scripting in column headersinfoEPSS 0.5%
- CVE-2026-47765: Frappe authorization bypass in document restore endpointsinfoEPSS 0.4%
- CVE-2026-47194: Frappe host header poisoning in magic login link generationinfoCVSS 7.1EPSS 0.3%
- CVE-2026-47185: Frappe Workspace Save API broken access controlinfoCVSS 6.5EPSS 0.4%
- CVE-2026-13227: ERPNext improper authorization in Prospect opportunities APIinfoEPSS 0.4%
- CVE-2026-12895: Frappe ERPNext SQL injection in Supplier recordsinfoCVSS 7.1
- CVE-2026-55242: Frappe ERPNext server-side template injection in configuration fieldshighCVSS 8.8
- CVE-2026-49394: Frappe authorization bypass in Workspace update_page endpointinfoCVSS 7.1
- CVE-2026-42219: Frappe path traversal in download_backupsinfoCVSS 6.9
- CVE-2026-41482: Frappe Framework path traversal in Chrome PDF GeneratorinfoCVSS 7.1
- CVE-2025-30212: PYSEC-2026-1390 - Frappe has possibility of SQL injection due to improper validationsmediumCVSS 4EPSS 0.4%
- CVE-2026-41581: Frappe Framework SQL injection in get_blog_listinfoCVSS 6.9EPSS 0.0%
- CVE-2026-42840: Frappe ERPNext stored XSS in POS customer fieldsinfoCVSS 5.1
Most severe Frappe vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-44442: Frappe ERPNext missing authorization in document modification endpointscriticalCVSS 9.9
- CVE-2026-38431: Frappe ERPNext SSTI in Email Template EnginecriticalCVSS 9.8EPSS 0.4%
- CVE-2025-67289: Frappe Framework and ERPNext Arbitrary File Upload in AttachmentscriticalCVSS 9.6EPSS 0.4%
- CVE-2026-39351: Frappe unrestricted Doctype access via API exploitcriticalCVSS 9.1EPSS 0.3%
- CVE-2026-31017: Frappe ERPNext and Frappe Framework SSRF in Print Format PDF generationcriticalCVSS 9.1EPSS 0.3%
- CVE-2026-55242: Frappe ERPNext server-side template injection in configuration fieldshighCVSS 8.8
- CVE-2026-44446: Frappe ERPNext SQL injection in multiple endpointshighCVSS 8.8
- CVE-2026-94113: Frappe ERPNext authorization bypass in timesheet endpointsmediumCVSS 6.5EPSS 0.4%
- CVE-2025-66581: Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, a…mediumCVSS 6.5EPSS 0.2%
- CVE-2026-45081: Frappe HR incorrect authorization in Leave Details APImediumCVSS 6.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 4 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 5 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 5 | 0 | |
| 24 Aug 2026 | 2 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 4 | 0 | |
| 21 Sep 2026 | 1 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/frappe.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Frappe vulnerabilities", https://junglewise.ai/threats/vendors/frappe, 26 September 2026.