CVE-2026-41581: Frappe Vulnerable to Possible SQL Injection via get_blog_list
Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Injection via getbloglist. This issue has been patched in versions 15.106.0 and 16.16.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 15.106.0 - Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 16.16.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41581?
The severity of CVE-2026-41581 is classified as medium with a score of 6.9.
How do I fix CVE-2026-41581?
To fix CVE-2026-41581, upgrade to Frappe versions 15.106.0 or 16.16.0 or later.
What type of vulnerability is CVE-2026-41581?
CVE-2026-41581 is classified as a SQL Injection vulnerability.
What components of Frappe are affected by CVE-2026-41581?
CVE-2026-41581 affects the get_blog_list function in previous versions of the Frappe framework.
When was CVE-2026-41581 published?
CVE-2026-41581 was published on June 12, 2026.