VendorsFrappeerpnextall versions
Vulnerabilities

Frappe ERPNext

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

59CVEs
CVE-2025-52050
In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_program/loyalty_program.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the expiry_date parameter.
Published 2025-09-30 · Analyzed
6.5EPSS 0.003
CVE-2025-52049
In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query into the timelog parameter.
Published 2025-09-30 · Analyzed
6.5EPSS 0.003
CVE-2025-52043
In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_accounts_importer.py is vulnerable to SQL injection, which allows an attacker to extract all information from databases by injecting a SQL query into the company parameter.
Published 2025-09-30 · Analyzed
6.5EPSS 0.003
CVE-2025-52047
In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the filters.disabled parameter.
Published 2025-09-30 · Analyzed
6.5EPSS 0.003
CVE-2026-44448
ERPNext: Unauthorised Document modification due to missing validation
Published 2026-05-13 · Analyzed
6.5EPSS 0.003
CVE-2022-28598
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.
Published 2022-08-22 · Modified
6.11 PoCEPSS 0.041
CVE-2018-11339
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
Published 2018-05-22 · Modified
6.11 PoCEPSS 0.040
CVE-2019-20511
ERPNext 11.1.47 allows blog?blog_category= Frame Injection.
Published 2020-03-18 · Modified
6.1EPSS 0.007
CVE-2026-38432
ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when the template is applied.
Published 2026-05-05 · Analyzed
6.1EPSS 0.003
CVE-2022-23055
ERPNext - Improper user access conrol
Published 2022-06-22 · Modified
5.5EPSS 0.012
CVE-2022-23057
ERPNext - Stored XSS in My Profile
Published 2022-06-22 · Modified
5.4EPSS 0.006
CVE-2025-56379
A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.
Published 2025-10-02 · Modified
5.4EPSS 0.004
CVE-2025-65923
A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1 when using the Update Existing Recordsoption. An attacker can embed malicious JavaScript code into a CSV field, which is then stored in the database and executed whenever the affected record is viewed by a user within the ERPNext web interface. This exposure may allow an attacker to compromise user sessions or perform unauthorized actions under the context of a victim's account.
Published 2026-02-03 · Analyzed
5.4EPSS 0.002
CVE-2026-44441
ERPNext: Possible SSRF by any authenticated user
Published 2026-05-13 · Analyzed
5.0EPSS 0.003
CVE-2025-66436
An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (terms) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a custom SandboxedEnvironment, several dangerous globals such as frappe.db.sql are still available in the execution context via get_safe_globals(). An authenticated attacker with access to create or modify a Terms and Conditions document can inject arbitrary Jinja expressions into the terms field, resulting in server-side code execution within a restricted but still unsafe context. This vulnerability can be used to leak database information.
Published 2025-12-15 · Analyzed
4.3EPSS 0.003
CVE-2025-66435
An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (contract_terms) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a custom SandboxedEnvironment, several dangerous globals such as frappe.db.sql are still available in the execution context via get_safe_globals(). An authenticated attacker with access to create or modify a Contract Template can inject arbitrary Jinja expressions into the contract_terms field, resulting in server-side code execution within a restricted but still unsafe context. This vulnerability can be used to leak database information.
Published 2025-12-15 · Analyzed
4.3EPSS 0.003
CVE-2025-65924
ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are intended for plain text. Although JavaScript is blocked (preventing XSS), the HTML is still preserved in the generated PDF document. As a result, an attacker can inject malicious clickable links into an ERP-generated PDF. Since PDF files generated by the ERP system are generally considered trustworthy, users are highly likely to click these links, potentially enabling phishing attacks or malware delivery. This issue occurs in the Add Quality Goal' function.
Published 2026-02-03 · Modified
4.1EPSS 0.002
CVE-2022-23056
ERPNext - Stored XSS leads to account takover
Published 2022-06-22 · Modified
3.5EPSS 0.009
CVE-2022-23058
ERPNext - Stored XSS in My Settings
Published 2022-06-22 · Modified
3.5EPSS 0.009
← Prev2 / 2