PatchSiren

Frappe CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Frappe CVE published 2026-09-28

CVE-2026-101006

A flaw in Frappe HR up to 16.15.0 allows incorrect authorization due to improper permission validation in the hrms/api/__init__.py file. This issue, affecting the functions get_expense_claims, get_shift_requests, and get_attendance_requests, can be exploited remotely. The vendor has acknowledged and fixed this issue, which was initially reported by another individual.

MEDIUM Frappe CVE published 2026-09-23

CVE-2026-96672

Frappe ERPNext versions before 16.34.1 have a vulnerability where Financial Report Template calculation_formula values are not validated to reference whitelisted methods before being passed to frappe.call(). This allows Accounts Managers to supply arbitrary dotted Python paths, potentially invoking non-whitelisted internal server-side methods and reading their return values.

HIGH Frappe CVE published 2026-09-20

CVE-2026-94113

CVE-2026-94113 debrief based on the supplied source corpus. Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to enumerate and retrieve billable time [truncated]

HIGH frappe CVE published 2026-08-30

CVE-2026-82634

The CVE-2026-82634 vulnerability is an authorization flaw in the render_jinja_template endpoint of Frappe Framework development builds. This flaw allows low-privileged users to render arbitrary Jinja templates by supplying raw template strings, potentially leading to unauthorized data access. Organizations using Frappe Framework development builds should be aware of this vulnerability and take steps to mi [truncated]

MEDIUM frappe CVE published 2026-08-27

CVE-2026-81731

The CVE-2026-81731 vulnerability affects Frappe versions 15.11.0 through 16.32.0, allowing stored XSS attacks via the Workspace Link doctype description field. This field's 'ignore_xss_filter' flag enables arbitrary markup injection by users with the Workspace Manager role, potentially leading to session token theft and authenticated requests as victims. Organizations should prioritize patching and restri [truncated]

HIGH frappe CVE published 2026-08-26

CVE-2026-66003

An access control bypass in the Frappe REST API allows a low-privileged authenticated user to read data from Linked DocTypes they are not authorized to access. This issue is fixed in version 15.115.0. The vulnerability arises from inconsistent enforcement of linked DocType permissions when records are retrieved through the REST API, enabling unauthorized data access. Defenders should assess exposure and a [truncated]

MEDIUM frappe CVE published 2026-08-20

CVE-2026-66002

The Frappe framework, a full-stack web application framework, has a vulnerability that allows remote attackers to enumerate registered users. This issue arises from distinguishable response shapes for registered and unregistered email addresses in the public request-data web form and PersonalDataDownloadRequest class. The vulnerability is fixed in versions 15.115.0 and 16.27.0. Organizations should be awa [truncated]

HIGH frappe CVE published 2026-08-20

CVE-2026-66001

An OAuth2 vulnerability in Frappe allows an attacker to cause an authenticated user to approve an OAuth grant or reuse authorization state for the wrong client, exposing data and permitting actions within the granted scopes. This issue arises from the approve and authorize functions in frappe/integrations/oauth2.py allowing the OAuth2 consent flow to proceed without restricting approve to POST, without a [truncated]

MEDIUM frappe CVE published 2026-08-20

CVE-2026-63654

CVE-2026-63654 is a vulnerability in Frappe, a full-stack web application framework, where the whitelisted endpoint for bulk workflow approvals accepts safe HTTP methods, allowing an attacker to induce an authenticated victim browser to submit an approval action with the victim's privileges. This vulnerability requires defenders to verify affected versions and assess exposure. The CVE record and NVD entry [truncated]

HIGH frappe CVE published 2026-08-20

CVE-2026-62315

CVE-2026-62315 is a high-severity vulnerability in Frappe, a full-stack web application framework. The vulnerability allows an authenticated caller to mass-assign protected fields through the client endpoint due to type confusion in the frappe.client.set_value function. This could lead to unauthorized data modification and potential privilege escalation. Defenders should assess exposure, especially in env [truncated]

MEDIUM frappe CVE published 2026-08-20

CVE-2026-53569

CVE-2026-53569 is a vulnerability in Frappe, a full-stack web application framework. The whitelisted endpoints toggle_like and mark_as_seen do not enforce read permission, allowing authenticated users to interact with documents or notes they cannot read. This discloses resource existence and modifies resource-associated metadata. The CVE record was published on 2026-08-20T19:16:54.350Z and was last modifi [truncated]

CRITICAL frappe CVE published 2026-08-17

CVE-2026-65974

ERPNext users should assess exposure and prioritize remediation due to a critical vulnerability allowing remote code execution. This vulnerability, tracked as CVE-2026-65974, affects ERPNext versions prior to 15.111.0 and 16.22.0. The issue allows limited authenticated users to cross a permission boundary in Frappe safe execution, leading to server-side template injection and remote code execution. Users [truncated]

HIGH frappe CVE published 2026-08-17

CVE-2026-65822

PatchSiren debrief for CVE-2026-65822, a HIGH severity vulnerability in ERPNext, a free and open-source Enterprise Resource Planning tool. The issue allows an authenticated user to extract sensitive information and manipulate database queries due to an unvalidated doctype filter in the inactive_customers.py report, which is fixed in versions 15.116.0 and 16.23.0.

CRITICAL frappe CVE published 2026-08-10

CVE-2026-72911

PatchSiren debrief for CVE-2026-72911, a critical vulnerability in ERPNext that allows authenticated users to inject template expressions and execute arbitrary server-side code. This issue is fixed in versions 15.118.0 and 16.29.0. The vulnerability has a CVSS score of 9.9 and affects versions prior to 15.118.0 and 16.29.0. ERPNext administrators and users, particularly those with common operational roles [truncated]

HIGH frappe CVE published 2026-08-10

CVE-2026-72910

ERPNext, a free and open-source Enterprise Resource Planning tool, had multiple functions lacking required write permission checks. This allowed authenticated limited users to modify protected data beyond their roles. The issue is fixed in versions 15.112.0 and 16.22.0. Affected deployments should be verified, and patches applied to prevent unauthorized data modification. Review user roles and permissions [truncated]

HIGH frappe CVE published 2026-08-10

CVE-2026-72909

CVE-2026-72909 is a vulnerability in ERPNext, a free and open-source Enterprise Resource Planning tool. The ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not apply Customer and Supplier user permissions to the Payment Ledger Entry dynamic-link party field. This allows any authenticated user to read unauthorized cross-company fina [truncated]

MEDIUM frappe CVE published 2026-08-10

CVE-2026-72908

A vulnerability in ERPNext, a free and open-source Enterprise Resource Planning tool, allows an authenticated low-privilege user to inject SQL and extract sensitive information. The issue arises from the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py, which constructs an SQL WHERE clause from request-influenced posting_date and args values. This problem is fixed in versions 15. [truncated]

MEDIUM frappe CVE published 2026-08-10

CVE-2026-72907

ERPNext, an open-source Enterprise Resource Planning tool, has a vulnerability in its add_ac function within erpnext/accounts/utils.py. This function accepts an ignore_permissions argument without properly enforcing Account create permissions. Consequently, an authenticated but limited user can create unauthorized accounting master records, potentially affecting financial data integrity and audit trails. [truncated]

MEDIUM frappe CVE published 2026-08-10

CVE-2026-72906

CVE-2026-72906 is a vulnerability in ERPNext, a free and open-source Enterprise Resource Planning tool. An authenticated low-privilege user can trigger automated emails outside the permitted role due to a missing Process Statement Of Accounts permission check in the send_auto_email function. This issue allows unauthorized email triggering, potentially leading to email-based attacks. Defenders should asses [truncated]

LOW frappe CVE published 2026-08-07

CVE-2026-66000

CVE-2026-66000 is a low-severity vulnerability in the Frappe web application framework that allows users to continue receiving document data by email even after their access has been revoked or reduced. This issue was fixed in versions 16.23.0 and 15.112.0. The vulnerability exists in the Document Follow notification generation of Frappe, allowing users with revoked or reduced access to continue receiving [truncated]

MEDIUM frappe CVE published 2026-08-07

CVE-2026-66058

CVE-2026-66058 is a vulnerability in the Frappe web application framework that allows unrestricted access to a Document Follow API for authenticated users. This issue was fixed in versions 16.20.0 and 15.112.0. The vulnerability has a medium severity and could allow potential unauthorized access to sensitive documents. Defenders should assess exposure and apply patches to prevent potential misuse of the D [truncated]

MEDIUM frappe CVE published 2026-08-07

CVE-2026-66059

A field-level permissions bypass in Frappe exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0. The vulnerability allows unauthorized access to sensitive data, potentially leading to data breaches or system compromise. Defenders should assess their exposure and prioritize patching or mitigating this vulnerability to prevent potential unauthorized access. The CVE record [truncated]

MEDIUM frappe CVE published 2026-08-06

CVE-2026-49391

CVE-2026-49391 is a medium-severity vulnerability in the Frappe web application framework that allows an authenticated importer to persist script content, which can execute when another user views the import interface. The issue is fixed in versions 16.19.0 and 15.109.0. This vulnerability exists in the Data Import feature of Frappe, where imported column headers are not properly escaped before rendering [truncated]

HIGH frappe CVE published 2026-08-06

CVE-2026-47765

CVE-2026-47765 debrief based on the supplied source corpus. The vulnerability in Frappe framework versions prior to 15.110.0 and 16.20.0 allows authenticated users to restore deleted documents without required authorization, impacting data integrity. Frappe framework administrators and users with access to the restore and bulk_restore endpoints should verify user authorization and document permissions to [truncated]

HIGH frappe CVE published 2026-08-06

CVE-2026-47194

CVE-2026-47194 is a high-severity vulnerability in the Frappe web application framework that allows remote attackers to manipulate temporary magic login links, potentially leading to unauthorized access. This issue, fixed in versions 15.108.0 and 16.18.3, requires immediate attention from developers and administrators of Frappe-based applications. Affected systems may be exposed to potential unauthorized [truncated]

HIGH frappe CVE published 2026-07-20

CVE-2026-39385

In Frappe LMS version 2.51.0 and earlier, a user could bypass payment validation for courses by using an unrelated batch. This issue has been patched in version 2.52.0, where enrollment now validates that the batch is linked to the course. The vulnerability class is related to insufficient validation checks in the enrollment process, allowing for potential unauthorized access to paid courses. This issue a [truncated]

MEDIUM frappe CVE published 2026-07-10

CVE-2026-58503

CVE-2026-58503 is a medium-severity vulnerability in Frappe, a full-stack web application framework. Prior to versions 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0. The vulnerability allows an attacker to enumerate users, which could lead to further targeted attacks. Users of Frappe framework, especially tho [truncated]

HIGH frappe CVE published 2026-07-10

CVE-2026-55852

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T22:16:43.970Z and has not been modified since then. Frappe framework versions prior to 16.23.0 and 15.112.0 are affected by TarSlip RCE vulnerability. Users should apply patches and review package import processes. This vulnerability allows for Remote Code Execution (RCE) due to insufficient chec [truncated]

HIGH frappe CVE published 2026-07-10

CVE-2026-49394

CVE-2026-49394 is an authorization bypass vulnerability in Frappe, a full-stack web application framework. The issue was fixed in version 16.19.0. The vulnerability affects the update_page endpoint in Workspace, allowing public workspaces to bypass the required Workspace Manager edit check. This issue has a high CVSS score of 7.1, indicating a high severity vulnerability. Users of Frappe framework, especi [truncated]

MEDIUM frappe CVE published 2026-07-10

CVE-2026-48127

CVE-2026-48127 is a vulnerability in Frappe, a full-stack web application framework. The issue affects file-handling API endpoints, such as add_attachments, allowing users without write access to attach files to any doctype. This vulnerability has been fixed in versions 16.20.0 and 15.110.0. Users should update to these versions or later to mitigate the issue. The vulnerability arises from insufficient ac [truncated]