CVE-2025-11461: Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard Controller
Published Nov 26, 2025
·Updated
Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. This issue affects Frappe CRM: 1.53.1.
Affected Software
2 affected components
Frappe CRM
Frappe Frappe CRM=1.53.1
Remediation
Patch Available
Event History
Nov 26, 2025
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-11461?
CVE-2025-11461 is categorized as a high severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2025-11461?
To fix CVE-2025-11461, update Frappe CRM to the latest version where the vulnerability is patched.
3
What versions are affected by CVE-2025-11461?
CVE-2025-11461 affects Frappe CRM version 1.53.1 and possibly earlier versions.
4
What could be the impact of exploiting CVE-2025-11461?
Exploitation of CVE-2025-11461 may allow attackers to execute arbitrary SQL queries, potentially compromising the database.
5
How can I detect if CVE-2025-11461 has been exploited?
You can detect exploitation of CVE-2025-11461 by monitoring logs for unusual database queries and unauthorized access attempts.