Frappe
89 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Frappe, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Frappe CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 4 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 3 |
| 2025-07 | 0 |
| 2025-08 | 2 |
| 2025-09 | 1 |
| 2025-10 | 4 |
| 2025-11 | 0 |
| 2025-12 | 5 |
| 2026-01 | 2 |
| 2026-02 | 1 |
| 2026-03 | 6 |
| 2026-04 | 5 |
| 2026-05 | 1 |
| 2026-06 | 11 |
| 2026-07 | 8 |
| 2026-08 | 16 |
| 2026-09 | 1 |
Severity
How the 89 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical8
- High20
- Medium26
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Frappe.
- CVE-2023-51769Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.6.1
- CVE-2026-82634Frappe Framework Development Branch Incorrect Authorization via Jinja Template Preview Endpoint6.5
- CVE-2026-81731Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description5.4
- CVE-2026-66003Frappe: Access control bypass via REST API dot-notation fields on linked doctypes—
- CVE-2026-66002Frappe: User Enumeration via PDDR—
- CVE-2026-66001Frappe: Improper Authorization in OAuth2 Consent Endpoint—
- CVE-2026-62315Frappe: Mass assignment via set_value—
- CVE-2026-63654Frappe: Unauthenticated Workflow approval via confirm_action—
- CVE-2026-53569Frappe: Missing authorization in toggle_like and mark_as_seen—
- CVE-2026-66000Frappe: Unrestricted access to Document Follow APIs—
- CVE-2025-58375Frappe has potential SQL Injection due to missing validation8.1
- CVE-2026-66058Frappe: Unrestricted access to a Document Follow API—
- CVE-2026-66059Frappe: Field-level permission bypass via Document Follow—
- CVE-2026-49391Frappe: Stored XSS in Column Headers via Data Import—
- CVE-2026-47765Frappe: Lack of Permissions in restore/bulk_restore—
Product grouping is registry-driven, with AI assist and human review. How it works