These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The Frappe full-stack web application framework has a vulnerability in its Data Import feature. Prior to versions 16.19.0 and 15.109.0, imported column headers are not escaped before rendering previews and results. This allows an authenticated importer to inject script content that will execute when another user views the import interface. The CVE record was published on 2026-08-06T22:17:14.360Z and has n [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:17:08.960Z and has not been modified since then. Frappe versions 15.110.0 and 16.20.0 or later address the issue. Organizations using Frappe should prioritize patching to prevent potential data exposure and review compensating controls for exposed systems. The vulnerability affects the restore [truncated]
Frappe is a full-stack web application framework. CVE-2026-47194 is a vulnerability in temporary magic login link generation, allowing remote attackers to cause emailed login links to point to an attacker-controlled domain and capture the login token. Organizations should be aware of this vulnerability and take steps to mitigate it by updating to versions 15.108.0 or 16.18.3. This issue has a CVSS score o [truncated]
In Frappe LMS version 2.51.0 and earlier, a user could bypass payment validation for courses by using an unrelated batch. This issue has been patched in version 2.52.0, where enrollment now validates that the batch is linked to the course. The vulnerability class is related to insufficient validation checks in the enrollment process, allowing for potential unauthorized access to paid courses. This issue a [truncated]
CVE-2026-58503 is a medium-severity vulnerability in Frappe, a full-stack web application framework. Prior to versions 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0. The vulnerability allows an attacker to enumerate users, which could lead to further targeted attacks. Users of Frappe framework, especially tho [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T22:16:43.970Z and has not been modified since then. Frappe framework versions prior to 16.23.0 and 15.112.0 are affected by TarSlip RCE vulnerability. Users should apply patches and review package import processes. This vulnerability allows for Remote Code Execution (RCE) due to insufficient chec [truncated]
CVE-2026-49394 is an authorization bypass vulnerability in Frappe, a full-stack web application framework. The issue was fixed in version 16.19.0. The vulnerability affects the update_page endpoint in Workspace, allowing public workspaces to bypass the required Workspace Manager edit check. This issue has a high CVSS score of 7.1, indicating a high severity vulnerability. Users of Frappe framework, especi [truncated]
CVE-2026-48127 is a vulnerability in Frappe, a full-stack web application framework. The issue affects file-handling API endpoints, such as add_attachments, allowing users without write access to attach files to any doctype. This vulnerability has been fixed in versions 16.20.0 and 15.110.0. Users should update to these versions or later to mitigate the issue. The vulnerability arises from insufficient ac [truncated]
Frappe is a full-stack web application framework. A vulnerability was found in an endpoint in reportview that lacked appropriate permission checks. This issue has been fixed in versions 15.107.5 and 16.18.2. Users of Frappe framework versions prior to these should review and apply the provided patches to prevent potential exploitation. The vulnerability has a CVSS score of 5.3 and MEDIUM severity.
CVE-2026-47199 is a low-severity vulnerability affecting Frappe's check_safe_sql_query functionality. Prior to versions 16.18.3 and 15.108.0, the function permitted SELECT INTO OUTFILE queries, which could potentially be exploited on self-hosted sites with misaligned database permissions and available MySQL FILE privileges. The issue is fixed in versions 16.18.3 and 15.108.0. This vulnerability has a low [truncated]
CVE-2026-42219 is a path traversal vulnerability in the Frappe framework, exploitable via the download_backups feature due to insufficient hardening. This vulnerability has been fixed in Frappe versions 16.19.0 and 15.109.0. Users of affected versions should apply patches to prevent path traversal attacks. The issue allows attackers to traverse paths, potentially leading to unauthorized access or data exp [truncated]
CVE-2026-41482 is a high-severity vulnerability in Frappe, a full-stack web application framework. The issue, fixed in version 16.18.3, allowed for possible path traversal and local file inclusion through secure local resource access in the Chrome PDF Generator. The vulnerability has a CVSS score of 7.1 and is classified as HIGH. Organizations should prioritize patching to version 16.18.3 or later, especi [truncated]
CVE-2026-53568 is a stored XSS vulnerability in the Frappe Report/List View. This issue was patched in versions 15.107.2 and 16.17.4. The vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severity.
CVE-2026-44976 is a vulnerability in Frappe, a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue has been patched in version 16.17.4. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM.
CVE-2026-44975 is a vulnerability in Frappe, a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users in the system. This issue has been patched in versions 15.107.2 and 16.17.4. The CVSS score for this vulnerability is 5.3, with a severity of MEDIUM.
CVE-2026-44208 is a vulnerability in the Frappe full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, the 'submit_discussion()' endpoint lacked validations, allowing for unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.17.0.
CVE-2026-44207 is a Medium severity vulnerability in Frappe, a full-stack web application framework. The issue, classified as an Insecure Direct Object Reference (IDOR), allows authenticated users to access other users' email configuration details. This vulnerability existed prior to Frappe versions 15.107.0 and 16.17.0, which have addressed the issue. The Common Vulnerability Scoring System (CVSS) score [truncated]
CVE-2026-44206 is a MEDIUM severity vulnerability in Frappe, a full-stack web application framework. Versions prior to 15.107.2 and 16.17.4 are affected by a DB Schema Enumeration vulnerability through an endpoint. This issue has been patched in versions 15.107.2 and 16.17.4. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].
CVE-2026-47739 is a MEDIUM severity vulnerability in Frappe, a full-stack web application framework. The vulnerability is due to lack of sanitization in Note, which allows for stored XSS. This issue has been patched in versions 15.106.0 and 16.16.0.
CVE-2026-44205 is a stored XSS vulnerability in the user profile image section of Frappe, a full-stack web application framework. This issue allows an attacker to execute malicious scripts in the browsers of other users. The vulnerability has been patched in version 15.106.0.
CVE-2026-41581 is a SQL Injection vulnerability in Frappe, a full-stack web application framework. The vulnerability is located in the `get_blog_list` function and has been patched in versions 15.106.0 and 16.16.0. The CVSS score for this vulnerability is 6.9, indicating a medium severity.
CVE-2026-46546 is a vulnerability in Frappe Learning Management System (LMS) prior to version 2.53.0. An authenticated user could supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigate to an attacker-chosen URL. This issue has been patched in version 2.53.0. The CVSS score for this vulnerability is 2.1, indicating a low severity.
CVE-2026-45081 is a medium-severity improper authorization vulnerability in Frappe HR, an open-source human resources management solution. The flaw, present in versions prior to 16.5.0, allows authenticated employees to access other employees' leave details due to missing authorization checks. The vulnerability was disclosed on May 27, 2026, and has been assigned a CVSS 3.1 score of 6.5 (MEDIUM). The issu [truncated]
CVE-2026-39405 is a critical path traversal issue in Frappe Learning Management System (LMS). The advisory says a user with course editing privileges could upload a SCORM ZIP package and write files outside the intended directory. The issue is resolved in version 2.50.1.
CVE-2026-39352 is a high-severity path traversal issue in Frappe that can lead to arbitrary file read. According to the published advisory material, versions prior to 15.105.0 and 16.15.0 are affected, and the issue is resolved in 15.105.0 and 16.15.0. Because the weakness is classified as CWE-22 and the CVSS score is 8.7, this should be treated as a priority patching item for any exposed or internally re [truncated]
CVE-2026-38432 is a Cross Site Scripting (XSS) vulnerability in ERPNext's Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that is executed on the victim's browser when the template is applied. This issue affects ERPNext version 15.103.1 and before. The vulnerability has a CVSS score of 6.1 and is classified as MEDIUM severity. Users [truncated]
CVE-2026-39351 is a medium-severity vulnerability in Frappe, a full-stack web application framework. The vulnerability allows unrestricted Doctype access via API exploit. This could allow attackers to gain unauthorized access and potentially lead to further exploitation. Administrators and users of Frappe framework versions prior to 16.14.0 and 15.104.0 should apply patches to prevent potential API exploi [truncated]