VendorsFrappeerpnext15.89.0
Vulnerabilities

Frappe ERPNext 15.89.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2025-67289
An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
Published 2025-12-22 · Modified
9.6EPSS 0.005