CVE-2025-55731: Frappe has the possibility of Authenticated SQL Injection due to improper validations
Published Aug 20, 2025
·Updated
Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15.
Affected Software
3 affected components
Frappe frappe<15.74.2, <14.96.15
Frappe frappe<14.96.15
Frappe frappe>=15.0.0<15.74.2
Remediation
Event History
Aug 20, 2025
CVE Published
via MITRE·03:22 PM
Data Sourced
via MITRE·03:22 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55731?
The severity of CVE-2025-55731 is considered high due to its potential for SQL injection leading to unauthorized data access.
2
How do I fix CVE-2025-55731?
To fix CVE-2025-55731, upgrade to Frappe version 15.74.2 or 14.96.15 or later.
3
What type of vulnerability is CVE-2025-55731?
CVE-2025-55731 is an SQL injection vulnerability affecting the Frappe framework.
4
What versions of Frappe are affected by CVE-2025-55731?
CVE-2025-55731 affects Frappe versions prior to 15.74.2 and 14.96.15.
5
Can CVE-2025-55731 lead to data breaches?
Yes, CVE-2025-55731 can lead to unauthorized data access, potentially resulting in data breaches.