Frappe Erpnext vulnerabilities
74 known vulnerabilities affecting frappe/erpnext.
Total CVEs
74
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH27MEDIUM36LOW2
Vulnerabilities
Page 2 of 4
CVE-2018-3883P3HIGHCVSS 8.8v10.1.62018-09-12
CVE-2018-3883 [HIGH] CWE-89 CVE-2018-3883: An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Spec
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The employee and sort_order parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are
nvd
CVE-2018-3885P3HIGHCVSS 8.8v10.1.62018-09-12
CVE-2018-3885 [HIGH] CWE-89 CVE-2018-3885: An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Spec
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The order_by parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.
nvd
CVE-2018-3882P3HIGHCVSS 8.8v10.1.62018-09-12
CVE-2018-3882 [HIGH] CWE-89 CVE-2018-3882: An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Spec
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The searchfield parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.
nvd
CVE-2026-44447P3HIGHCVSS 7.5fixed in 16.9.02026-05-13
CVE-2026-44447 [HIGH] CWE-89 CVE-2026-44447: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 16.9.0.
nvd
CVE-2026-12895P3HIGHCVSS 7.1fixed in 15.111.0fixed in 16.22.02026-07-29
CVE-2026-12895 [HIGH] CWE-89 CVE-2026-12895: SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application co
SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing parameterized queries, allowing the name (docname) of a Supplier record containing SQL metacharacters to be interpreted as part of the query. Exploitation of
nvd
CVE-2026-55242P3HIGHCVSS 8.8fixed in 15.111.0v>= 16.0.0, < 16.22.02026-07-15
CVE-2026-55242 [HIGH] CWE-863 CVE-2026-55242: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0,
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data outside the user's normal permission scope. This issue is fixed in versions 15.1
nvd
CVE-2025-52041P3HIGHCVSS 8.2v15.57.52025-10-01
CVE-2025-52041 [HIGH] CWE-89 CVE-2025-52041: In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_recon
In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reconciliation.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the inventory_dimensions_dict parameter.
nvd
CVE-2025-52039P3HIGHCVSS 8.2v15.57.52025-10-01
CVE-2025-52039 [HIGH] CWE-89 CVE-2025-52039: In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/d
In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_request/material_request.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the txt parameter.
nvd
CVE-2025-52040P3HIGHCVSS 8.2v15.57.52025-10-01
CVE-2025-52040 [HIGH] CWE-89 CVE-2025-52040: In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vu
In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker can extract all information from databases by injecting a SQL query into the blanket_order_type parameter.
nvd
CVE-2025-52042P3HIGHCVSS 8.2v15.57.52025-10-01
CVE-2025-52042 [HIGH] CWE-89 CVE-2025-52042: In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/requ
In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/request_for_quotation/request_for_quotation.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query via the txt parameter.
nvd
CVE-2026-44446P3HIGHCVSS 7.5fixed in 15.104.3≥ 16.0.0, < 16.14.0+1 more2026-05-13
CVE-2026-44446 [HIGH] CWE-89 CVE-2026-44446: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0,
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 15.104.3 and 16.14.0.
nvd
CVE-2026-65822P3HIGHCVSS 7.6fixed in 15.116.0v>= 16.0.0, < 16.23.02026-08-17
CVE-2026-65822 [HIGH] CWE-89 CVE-2026-65822: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0,
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates it into raw SQL in get_sales_details and get_last_sales_amt, allowing an authenticated user to extract sensitive information and manipul
nvd
CVE-2025-52044P3HIGHCVSS 7.5v15.57.52025-09-16
CVE-2025-52044 [HIGH] CWE-89 CVE-2025-52044: In Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is vulnerable
In Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query into inventory_dimensions_dict parameter.
nvd
CVE-2018-20061P3HIGHCVSS 7.5≥ 10.0.0, ≤ 10.1.76≥ 11.0.0, < 11.0.3+1 more2018-12-11
CVE-2018-20061 [HIGH] CWE-89 CVE-2018-20061: A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is
A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, many ERPNext sites allow account creation via the web. No special privileges are needed to conduct the attack. By calling a JavaScript function that calls a server-side Python function with carefully chosen a
nvd
CVE-2026-72910P3HIGHCVSS 7.1fixed in 15.112.0v>= 16.0.0, < 16.22.02026-08-10
CVE-2026-72910 [HIGH] CWE-862 CVE-2026-72910: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0,
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions across erpnext/accounts/doctype/account/account.py, erpnext/accounts/doctype/process_payment_reconciliation/process_payment_reconciliation.py
nvd
CVE-2025-65267P3CRITICALCVSS 9.0v15.83.22025-12-03
CVE-2025-65267 [CRITICAL] CWE-79 CVE-2025-65267: In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images
In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploitation may lead to account takeover, privilege esca
nvd
CVE-2026-72909P3HIGHCVSS 7.1fixed in 15.112.0v>= 16.0.0, < 16.23.02026-08-10
CVE-2026-72909 [HIGH] CWE-284 CVE-2026-72909: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0,
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not apply Customer and Supplier user permissions to the Payment Ledger Entry dynamic-link party field, allowing any authenticat
nvd
CVE-2026-44445P3MEDIUMCVSS 6.5fixed in 15.104.3≥ 16.0.0, < 16.12.0+1 more2026-05-13
CVE-2026-44445 [MEDIUM] CWE-611 CVE-2026-44445: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0,
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enables an authenticated attacker to read files from the local file system, including sensitive configuration files. This vulnerability is fixed in 15.104.3
nvd
CVE-2026-13227P3HIGHCVSS 7.1fixed in 15.115.0fixed in 16.26.02026-08-04
CVE-2026-13227 [HIGH] CWE-862 CVE-2026-13227: An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to in
An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities.
This issue affects ERPNext: before 15.115.0, before 16.26.0.
nvd
CVE-2026-72907P3MEDIUMCVSS 6.5fixed in 15.111.0v>= 16.0.0, < 16.22.02026-08-10
CVE-2026-72907 [MEDIUM] CWE-285 CVE-2026-72907: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0,
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without enforcing Account create permission, allowing an authenticated limited user to create unauthorized accounting master records and affect financial data inte
nvd