VendorsFrappeerpnext15.67.0
Vulnerabilities

Frappe ERPNext 15.67.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2025-56380
Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endpoint and a crafted script to the fieldname parameter
Published 2025-10-02 · Analyzed
6.5EPSS 0.003
CVE-2025-56381
ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the order_by and group_by parameters.
Published 2025-10-02 · Analyzed
6.5EPSS 0.003
CVE-2025-56379
A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.
Published 2025-10-02 · Modified
5.4EPSS 0.004