Frappe Erpnext vulnerabilities
74 known vulnerabilities affecting frappe/erpnext.
Total CVEs
74
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH27MEDIUM36LOW2
Vulnerabilities
Page 3 of 4
CVE-2026-72908P3MEDIUMCVSS 6.5fixed in 15.109.0v>= 16.0.0, < 16.20.02026-08-10
CVE-2026-72908 [MEDIUM] CWE-89 CVE-2026-72908: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0,
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WHERE clause from request-influenced posting_date and args values, allowing an authenticated low-privilege user to inject SQL and extract sensitive informat
nvd
CVE-2025-56381P3MEDIUMCVSS 6.5v15.67.02025-10-02
CVE-2025-56381 [MEDIUM] CWE-89 CVE-2025-56381: ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method
ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the order_by and group_by parameters.
nvd
CVE-2025-52050P3MEDIUMCVSS 6.5v15.57.52025-09-30
CVE-2025-52050 [MEDIUM] CWE-89 CVE-2025-52050: In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/account
In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_program/loyalty_program.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the expiry_date parameter.
nvd
CVE-2026-94113P3MEDIUMCVSS 6.5fixed in 15.121.0≥ 16.0.0, < 16.34.02026-09-20
CVE-2026-94113 [MEDIUM] CWE-862 CVE-2026-94113: Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vu
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to enumerate and retrieve billable time lo
nvd
CVE-2025-56380P3MEDIUMCVSS 6.5v15.67.02025-10-02
CVE-2025-56380 [MEDIUM] CWE-89 CVE-2025-56380: Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname
Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endpoint and a crafted script to the fieldname parameter
nvd
CVE-2025-52049P3MEDIUMCVSS 6.5v15.57.52025-09-30
CVE-2025-52049 [MEDIUM] CWE-89 CVE-2025-52049: In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/tim
In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query into the timelog parameter.
nvd
CVE-2025-52047P3MEDIUMCVSS 6.5v15.57.52025-09-30
CVE-2025-52047 [MEDIUM] CWE-89 CVE-2025-52047: In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is v
In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the filters.disabled parameter.
nvd
CVE-2025-52043P3MEDIUMCVSS 6.5v15.57.52025-09-30
CVE-2025-52043 [MEDIUM] CWE-89 CVE-2025-52043: In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_
In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_accounts_importer.py is vulnerable to SQL injection, which allows an attacker to extract all information from databases by injecting a SQL query into the company parameter.
nvd
CVE-2026-44448P3MEDIUMCVSS 6.5fixed in 15.102.0≥ 16.0.0, < 16.11.0+1 more2026-05-13
CVE-2026-44448 [MEDIUM] CWE-862 CVE-2026-44448: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0,
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 15.102.0 and 16.11.0.
nvd
CVE-2026-96672P3MEDIUMCVSS 6.4≥ 16.0.0, < 16.34.12026-09-23
CVE-2026-96672 [MEDIUM] CWE-470 CVE-2026-96672: Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_f
Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply arbitrary dotted Python paths to invoke non-whitelisted internal server-side methods and read their return values.
nvd
CVE-2026-44440P3MEDIUMCVSS 5.7fixed in 15.101.1≥ 16.0.0, < 16.10.0+1 more2026-05-13
CVE-2026-44440 [MEDIUM] CWE-22 CVE-2026-44440: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0,
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on an endpoint allows an authenticated adjacent attacker to read arbitrary files. This vulnerability is fixed in 15.101.1 and 16.10.0.
nvd
CVE-2026-42840P4MEDIUMCVSS 5.1v16.16.02026-06-03
CVE-2026-42840 [MEDIUM] CWE-79 CVE-2026-42840: An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a
An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of Sale (POS) interface for every operator who selects that customer.
This issue affects ERPNext: 16.16.0.
nvd
CVE-2025-65923P4MEDIUMCVSS 5.4≤ 15.88.12026-02-03
CVE-2025-65923 [MEDIUM] CWE-79 CVE-2025-65923: A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of
A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1 when using the Update Existing Recordsoption. An attacker can embed malicious JavaScript code into a CSV field, which is then stored in the database and executed whenever the affected record is viewed by a user within the ERPNext we
nvd
CVE-2025-66435P4MEDIUMCVSS 4.3≤ 15.89.02025-12-15
CVE-2025-66435 [MEDIUM] CWE-94 CVE-2025-66435: An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of
An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (contract_terms) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a custom SandboxedEnvironment, several dangerous globals
nvd
CVE-2025-66436P4MEDIUMCVSS 4.3≤ 15.89.02025-12-15
CVE-2025-66436 [MEDIUM] CWE-94 CVE-2025-66436: An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method
An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (terms) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a custom SandboxedEnvironment, several dangerous globals such
nvd
CVE-2019-20511P4MEDIUMCVSS 6.1v11.1.472020-03-18
CVE-2019-20511 [MEDIUM] CWE-79 CVE-2019-20511: ERPNext 11.1.47 allows blog?blog_category= Frame Injection.
ERPNext 11.1.47 allows blog?blog_category= Frame Injection.
nvd
CVE-2026-38432P4MEDIUMCVSS 6.1≤ 15.103.12026-05-05
CVE-2026-38432 [MEDIUM] CWE-79 CVE-2026-38432: ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engin
ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when the template is applied.
nvd
CVE-2022-23055P4MEDIUMCVSS 5.5≥ 11.0.4, < 13.1.0v11.0.32022-06-22
CVE-2022-23055 [MEDIUM] CWE-862 CVE-2022-23055: In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the ch
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of
nvd
CVE-2022-23057P4MEDIUMCVSS 5.4≥ 12.0.9, < 13.1.02022-06-22
CVE-2022-23057 [MEDIUM] CWE-79 CVE-2022-23057: In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to us
In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.
nvd
CVE-2026-42839P4MEDIUMCVSS 4.8v16.16.02026-06-03
CVE-2026-42839 [MEDIUM] CWE-79 CVE-2026-42839: An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScrip
An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, description, or image fields of an Item and trigger unescaped rendering in the Point of Sale (POS) cart interface for every operator who adds that item to a transaction.This issue affects ERPNext: 16.16.0.
nvd