frappe
8 known vulnerabilities affecting frappe products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-38431 | High | 0.4% | 9.8 | ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SS… | |
| CVE-2026-39351 | Medium | 0.3% | 9.1 | Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0,… | |
| CVE-2026-31017 | Medium | 0.2% | 9.1 | A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format fu… | |
| CVE-2026-39415 | Low | 0.3% | 4.3 | Frappe Learning Management System (LMS) is a learning system that helps users st… | |
| CVE-2026-34606 | Low | 0.2% | 6.1 | Frappe Learning Management System (LMS) is a learning system that helps users st… | |
| CVE-2026-38432 | Low | 0.2% | 6.1 | ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the … | |
| CVE-2026-81731 | Low | 0.2% | 5.4 | Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description… | |
| CVE-2026-46546 | Low | 0.1% | 5.4 | Frappe Learning Management System (LMS) is a learning system that helps users st… |