Where
-Infinity
0

Frappe frappeFrappe vuilnerable to an open redirect on login page

Risk 27
Severity
6.1
EPSS
0.04%
First published (updated )

Frappe frappeFrappe File Permissions can by bypassed using certain endpoints

Risk 43
Severity
8.1
EPSS
0.04%
First published (updated )

Frappe frappeFrappe SQL Injection from reporting logic

Risk 43
Severity
7.5
First published (updated )

Frappe frappeFrappe vulnerable to HTML injection by any Desk user

Risk 34
Severity
5.4
First published (updated )

Frappe Frappe LMSCross-site Scripting (XSS) - Generic in frappe/lms

Risk 35
Severity
7.1
EPSS
0.08%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frappe Frappe LMSFrappe LMS SQL Injection Issue on People Page

Risk 86
Severity
9.8
First published (updated )

Frappe frappePossibility limited SQL injection due to insufficient validation in Frappe

Risk 43
Severity
7.5
First published (updated )

Frappe frappeFrappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

Risk 27
Severity
5.3
First published (updated )

Frappe frappeIn two-factor authentication, the system also sending 2fa secret key in response, which enables an i…

Risk 43
Severity
7.5
First published (updated )

Frappe frappeIn core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Pr…

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frappe frappeXSS

Risk 38
Severity
6.1
First published (updated )

Frappe frappeCode Injection

Risk 86
Severity
9.8
First published (updated )

Frappe frappeSQL Injection

Risk 79
Severity
8.8
First published (updated )

Frappe frappeXSS

Risk 38
Severity
6.1
First published (updated )

Frappe frappeSQL Injection

Risk 79
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203