{"schema_version":1,"title":"Frappe Technologies vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 18 vulnerabilities in Frappe Technologies: 0 in the last 7 days and 5 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-58503, was published on 10 July 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/frappe-technologies","json_url":"https://junglewise.ai/threats/vendors/frappe-technologies.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/frappe-technologies","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":0,"all_time":18,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":5,"last_365_days":18},"latest":[{"cve":"CVE-2026-58503","cvss":6.9,"slug":"cve-2026-58503-frappe-framework-user-enumeration-in-reset-password-endpoint","title":"Frappe Framework user enumeration in reset_password endpoint","severity":"info","exploited":false,"published_at":"2026-07-10T22:16:44.783+00:00","url":"https://junglewise.ai/threats/cve-2026-58503-frappe-framework-user-enumeration-in-reset-password-endpoint"},{"cve":"CVE-2026-48127","cvss":5.3,"slug":"cve-2026-48127-frappe-framework-missing-authorization-in-file-handling-api","title":"Frappe Framework missing authorization in file-handling API","severity":"info","exploited":false,"published_at":"2026-07-10T22:16:42.14+00:00","url":"https://junglewise.ai/threats/cve-2026-48127-frappe-framework-missing-authorization-in-file-handling-api"},{"cve":"CVE-2026-47422","cvss":5.3,"slug":"cve-2026-47422-frappe-framework-missing-authorization-in-reportview","title":"Frappe Framework missing authorization in reportview","severity":"info","exploited":false,"published_at":"2026-07-10T22:16:42.007+00:00","url":"https://junglewise.ai/threats/cve-2026-47422-frappe-framework-missing-authorization-in-reportview"},{"cve":"CVE-2026-47199","cvss":2.3,"slug":"cve-2026-47199-frappe-framework-sql-injection-via-select-into-outfile-in-safe","title":"Frappe Framework SQL injection via SELECT INTO OUTFILE in safe_exec","severity":"info","exploited":false,"published_at":"2026-07-10T22:16:41.87+00:00","url":"https://junglewise.ai/threats/cve-2026-47199-frappe-framework-sql-injection-via-select-into-outfile-in-safe"},{"cve":"CVE-2026-42219","cvss":6.9,"slug":"cve-2026-42219-frappe-path-traversal-in-download-backups","title":"Frappe path traversal in download_backups","severity":"info","exploited":false,"published_at":"2026-07-10T22:16:41.55+00:00","url":"https://junglewise.ai/threats/cve-2026-42219-frappe-path-traversal-in-download-backups"},{"cve":"CVE-2026-50698","cvss":4.6,"slug":"cve-2026-50698-frappe-framework-stored-xss-in-audit-trail","title":"Frappe Framework stored XSS in Audit Trail","severity":"info","exploited":false,"published_at":"2026-06-24T15:16:40.873+00:00","url":"https://junglewise.ai/threats/cve-2026-50698-frappe-framework-stored-xss-in-audit-trail"},{"cve":"CVE-2026-53568","cvss":6.9,"epss":0.0002,"slug":"cve-2026-53568-frappe-framework-stored-xss-in-report-or-list-view","title":"Frappe Framework stored XSS in Report or List View","severity":"info","exploited":false,"published_at":"2026-06-12T16:16:33.81+00:00","url":"https://junglewise.ai/threats/cve-2026-53568-frappe-framework-stored-xss-in-report-or-list-view"},{"cve":"CVE-2026-50026","cvss":6.9,"epss":0.0003,"slug":"cve-2026-50026-frappe-framework-missing-authorization-in-relink-and-set-email","title":"Frappe Framework missing authorization in relink and set_email_password","severity":"info","exploited":false,"published_at":"2026-06-12T16:16:31.58+00:00","url":"https://junglewise.ai/threats/cve-2026-50026-frappe-framework-missing-authorization-in-relink-and-set-email"},{"cve":"CVE-2026-44976","cvss":5.3,"epss":0.0002,"slug":"cve-2026-44976-frappe-idor-in-update-onboarding-step","title":"Frappe IDOR in update_onboarding_step","severity":"info","exploited":false,"published_at":"2026-06-12T16:16:28.26+00:00","url":"https://junglewise.ai/threats/cve-2026-44976-frappe-idor-in-update-onboarding-step"},{"cve":"CVE-2026-44975","cvss":5.3,"epss":0.0002,"slug":"cve-2026-44975-frappe-missing-authorization-in-onboarding-reset","title":"Frappe missing authorization in onboarding reset","severity":"info","exploited":false,"published_at":"2026-06-12T16:16:28.12+00:00","url":"https://junglewise.ai/threats/cve-2026-44975-frappe-missing-authorization-in-onboarding-reset"},{"cve":"CVE-2026-44208","cvss":6.9,"epss":0.0003,"slug":"cve-2026-44208-frappe-framework-idor-in-submit-discussion-endpoint","title":"Frappe Framework IDOR in submit_discussion endpoint","severity":"info","exploited":false,"published_at":"2026-06-12T16:16:27.843+00:00","url":"https://junglewise.ai/threats/cve-2026-44208-frappe-framework-idor-in-submit-discussion-endpoint"},{"cve":"CVE-2026-44207","cvss":6.9,"epss":0.0002,"slug":"cve-2026-44207-frappe-framework-idor-in-email-configuration","title":"Frappe Framework IDOR in email configuration","severity":"info","exploited":false,"published_at":"2026-06-12T16:16:27.713+00:00","url":"https://junglewise.ai/threats/cve-2026-44207-frappe-framework-idor-in-email-configuration"},{"cve":"CVE-2026-44206","cvss":6.9,"epss":0.0002,"slug":"cve-2026-44206-frappe-framework-db-schema-enumeration-via-endpoint","title":"Frappe Framework DB schema enumeration via endpoint","severity":"info","exploited":false,"published_at":"2026-06-12T16:16:27.583+00:00","url":"https://junglewise.ai/threats/cve-2026-44206-frappe-framework-db-schema-enumeration-via-endpoint"},{"cve":"CVE-2026-39405","cvss":9.4,"slug":"cve-2026-39405-frappe-lms-path-traversal-in-scorm-zip-upload","title":"Frappe LMS path traversal in SCORM ZIP upload","severity":"info","exploited":false,"published_at":"2026-05-20T20:16:39.697+00:00","url":"https://junglewise.ai/threats/cve-2026-39405-frappe-lms-path-traversal-in-scorm-zip-upload"},{"cve":"CVE-2026-3673","cvss":5.4,"slug":"cve-2026-3673-frappe-framework-stored-xss-in-tag-pill-renderer","title":"Frappe Framework stored XSS in Tag Pill Renderer","severity":"medium","exploited":false,"published_at":"2026-04-22T20:16:41.79+00:00","url":"https://junglewise.ai/threats/cve-2026-3673-frappe-framework-stored-xss-in-tag-pill-renderer"},{"cve":"CVE-2026-39415","cvss":4.3,"epss":0.0026,"slug":"cve-2026-39415-frappe-lms-client-side-quiz-score-manipulation","title":"Frappe LMS client-side quiz score manipulation","severity":"medium","exploited":false,"published_at":"2026-04-08T21:16:59.033+00:00","url":"https://junglewise.ai/threats/cve-2026-39415-frappe-lms-client-side-quiz-score-manipulation"},{"cve":"CVE-2026-39351","cvss":9.1,"epss":0.0026,"slug":"cve-2026-39351-frappe-unrestricted-doctype-access-via-api-exploit","title":"Frappe unrestricted Doctype access via API exploit","severity":"critical","exploited":false,"published_at":"2026-04-07T19:16:46.213+00:00","url":"https://junglewise.ai/threats/cve-2026-39351-frappe-unrestricted-doctype-access-via-api-exploit"},{"cve":"CVE-2026-34606","cvss":6.1,"epss":0.0019,"slug":"cve-2026-34606-frappe-lms-stored-xss-in-lesson-content","title":"Frappe LMS stored XSS in lesson content","severity":"medium","exploited":false,"published_at":"2026-04-02T18:16:32.17+00:00","url":"https://junglewise.ai/threats/cve-2026-34606-frappe-lms-stored-xss-in-lesson-content"}],"vendor":{"hub":true,"name":"Frappe Technologies","slug":"frappe-technologies","homepage":"https://frappe.io/","description":"Frappe Technologies is an open-source software company known for the Frappe Framework and ERPNext.","url":"https://junglewise.ai/threats/vendors/frappe-technologies"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-39351","cvss":9.1,"epss":0.0026,"slug":"cve-2026-39351-frappe-unrestricted-doctype-access-via-api-exploit","title":"Frappe unrestricted Doctype access via API exploit","severity":"critical","exploited":false,"published_at":"2026-04-07T19:16:46.213+00:00","url":"https://junglewise.ai/threats/cve-2026-39351-frappe-unrestricted-doctype-access-via-api-exploit"},{"cve":"CVE-2026-34606","cvss":6.1,"epss":0.0019,"slug":"cve-2026-34606-frappe-lms-stored-xss-in-lesson-content","title":"Frappe LMS stored XSS in lesson content","severity":"medium","exploited":false,"published_at":"2026-04-02T18:16:32.17+00:00","url":"https://junglewise.ai/threats/cve-2026-34606-frappe-lms-stored-xss-in-lesson-content"},{"cve":"CVE-2026-3673","cvss":5.4,"slug":"cve-2026-3673-frappe-framework-stored-xss-in-tag-pill-renderer","title":"Frappe Framework stored XSS in Tag Pill Renderer","severity":"medium","exploited":false,"published_at":"2026-04-22T20:16:41.79+00:00","url":"https://junglewise.ai/threats/cve-2026-3673-frappe-framework-stored-xss-in-tag-pill-renderer"},{"cve":"CVE-2026-39415","cvss":4.3,"epss":0.0026,"slug":"cve-2026-39415-frappe-lms-client-side-quiz-score-manipulation","title":"Frappe LMS client-side quiz score manipulation","severity":"medium","exploited":false,"published_at":"2026-04-08T21:16:59.033+00:00","url":"https://junglewise.ai/threats/cve-2026-39415-frappe-lms-client-side-quiz-score-manipulation"},{"cve":"CVE-2026-39405","cvss":9.4,"slug":"cve-2026-39405-frappe-lms-path-traversal-in-scorm-zip-upload","title":"Frappe LMS path traversal in SCORM ZIP upload","severity":"info","exploited":false,"published_at":"2026-05-20T20:16:39.697+00:00","url":"https://junglewise.ai/threats/cve-2026-39405-frappe-lms-path-traversal-in-scorm-zip-upload"},{"cve":"CVE-2026-50026","cvss":6.9,"epss":0.0003,"slug":"cve-2026-50026-frappe-framework-missing-authorization-in-relink-and-set-email","title":"Frappe Framework missing authorization in relink and set_email_password","severity":"info","exploited":false,"published_at":"2026-06-12T16:16:31.58+00:00","url":"https://junglewise.ai/threats/cve-2026-50026-frappe-framework-missing-authorization-in-relink-and-set-email"},{"cve":"CVE-2026-44208","cvss":6.9,"epss":0.0003,"slug":"cve-2026-44208-frappe-framework-idor-in-submit-discussion-endpoint","title":"Frappe Framework IDOR in submit_discussion endpoint","severity":"info","exploited":false,"published_at":"2026-06-12T16:16:27.843+00:00","url":"https://junglewise.ai/threats/cve-2026-44208-frappe-framework-idor-in-submit-discussion-endpoint"},{"cve":"CVE-2026-53568","cvss":6.9,"epss":0.0002,"slug":"cve-2026-53568-frappe-framework-stored-xss-in-report-or-list-view","title":"Frappe Framework stored XSS in Report or List View","severity":"info","exploited":false,"published_at":"2026-06-12T16:16:33.81+00:00","url":"https://junglewise.ai/threats/cve-2026-53568-frappe-framework-stored-xss-in-report-or-list-view"},{"cve":"CVE-2026-44207","cvss":6.9,"epss":0.0002,"slug":"cve-2026-44207-frappe-framework-idor-in-email-configuration","title":"Frappe Framework IDOR in email configuration","severity":"info","exploited":false,"published_at":"2026-06-12T16:16:27.713+00:00","url":"https://junglewise.ai/threats/cve-2026-44207-frappe-framework-idor-in-email-configuration"},{"cve":"CVE-2026-44206","cvss":6.9,"epss":0.0002,"slug":"cve-2026-44206-frappe-framework-db-schema-enumeration-via-endpoint","title":"Frappe Framework DB schema enumeration via endpoint","severity":"info","exploited":false,"published_at":"2026-06-12T16:16:27.583+00:00","url":"https://junglewise.ai/threats/cve-2026-44206-frappe-framework-db-schema-enumeration-via-endpoint"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Frappe Technologies Frappe Framework","slug":"frappe-framework","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/frappe-framework"},{"name":"Frappe Technologies LMS","slug":"lms","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/lms"}]}