CVE Tools

Frappe

89 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Frappe, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Frappe CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Frappe CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-034
2025-040
2025-050
2025-063
2025-070
2025-082
2025-091
2025-104
2025-110
2025-125
2026-012
2026-021
2026-036
2026-045
2026-051
2026-0611
2026-078
2026-0816
2026-091

Severity

How the 89 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical814%
  • High2036%
  • Medium2646%
  • Low24%

Latest CVEs

The 15 most recently published vulnerabilities affecting Frappe.

  1. CVE-2023-51769Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.6.1
  2. CVE-2026-82634Frappe Framework Development Branch Incorrect Authorization via Jinja Template Preview Endpoint6.5
  3. CVE-2026-81731Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description5.4
  4. CVE-2026-66003Frappe: Access control bypass via REST API dot-notation fields on linked doctypes—
  5. CVE-2026-66002Frappe: User Enumeration via PDDR—
  6. CVE-2026-66001Frappe: Improper Authorization in OAuth2 Consent Endpoint—
  7. CVE-2026-62315Frappe: Mass assignment via set_value—
  8. CVE-2026-63654Frappe: Unauthenticated Workflow approval via confirm_action—
  9. CVE-2026-53569Frappe: Missing authorization in toggle_like and mark_as_seen—
  10. CVE-2026-66000Frappe: Unrestricted access to Document Follow APIs—
  11. CVE-2025-58375Frappe has potential SQL Injection due to missing validation8.1
  12. CVE-2026-66058Frappe: Unrestricted access to a Document Follow API—
  13. CVE-2026-66059Frappe: Field-level permission bypass via Document Follow—
  14. CVE-2026-49391Frappe: Stored XSS in Column Headers via Data Import—
  15. CVE-2026-47765Frappe: Lack of Permissions in restore/bulk_restore—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store