cbcvebase.

Frappe Erpnext vulnerabilities

74 known vulnerabilities affecting frappe/erpnext.

Total CVEs
74
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH27MEDIUM36LOW2

Vulnerabilities

Page 4 of 4
CVE-2019-20520P4MEDIUMCVSS 6.1v11.1.472020-03-19
CVE-2019-20520 [MEDIUM] CWE-79 CVE-2019-20520: ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI. ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.
nvd
CVE-2025-56379P4MEDIUMCVSS 5.4v15.67.02025-10-02
CVE-2025-56379 [MEDIUM] CWE-79 CVE-2025-56379: A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allow A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.
nvd
CVE-2026-72906P4MEDIUMCVSS 4.3fixed in 15.111.0v>= 16.0.0, < 16.22.02026-08-10
CVE-2026-72906 [MEDIUM] CWE-862 CVE-2026-72906: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py lacks a Process Statement Of Accounts permission check, allowing an authenticated low-privilege user to trigger automated emails out
nvd
CVE-2026-44441P4MEDIUMCVSS 4.3fixed in 15.106.0≥ 16.0.0, < 16.16.0+1 more2026-05-13
CVE-2026-44441 [MEDIUM] CWE-918 CVE-2026-44441: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in 15.106.0 and 16.16.0.
nvd
CVE-2019-20521P4MEDIUMCVSS 6.1v11.1.472020-03-19
CVE-2019-20521 [MEDIUM] CWE-79 CVE-2019-20521: ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI. ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.
nvd
CVE-2019-20516P4MEDIUMCVSS 6.1v11.1.472020-03-19
CVE-2019-20516 [MEDIUM] CWE-79 CVE-2019-20516: ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI. ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.
nvd
CVE-2019-20514P4MEDIUMCVSS 6.1v11.1.472020-03-19
CVE-2019-20514 [MEDIUM] CWE-79 CVE-2019-20514: ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI. ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.
nvd
CVE-2019-20515P4MEDIUMCVSS 6.1v11.1.472020-03-19
CVE-2019-20515 [MEDIUM] CWE-79 CVE-2019-20515: ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI. ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.
nvd
CVE-2019-20519P4MEDIUMCVSS 6.1v11.1.472020-03-19
CVE-2019-20519 [MEDIUM] CWE-79 CVE-2019-20519: ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafte ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.
nvd
CVE-2019-20517P4MEDIUMCVSS 6.1v11.1.472020-03-19
CVE-2019-20517 [MEDIUM] CWE-79 CVE-2019-20517: ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI. ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.
nvd
CVE-2019-20518P4MEDIUMCVSS 6.1v11.1.472020-03-19
CVE-2019-20518 [MEDIUM] CWE-79 CVE-2019-20518: ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI. ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
nvd
CVE-2025-65924P4MEDIUMCVSS 4.1≤ 15.88.12026-02-03
CVE-2025-65924 [MEDIUM] CWE-80 CVE-2025-65924: ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `` hyperlinks in fields that are intended for plain text. Although JavaScript is blocked (preventing XSS), the HTML is still preserved in the generated PDF document. As a result, an attacker can inject malicious clickable links into an ERP-generated PDF. Since PDF files ge
nvd
CVE-2022-23058P4LOWCVSS 3.5≥ 12.0.9, < 13.1.02022-06-22
CVE-2022-23058 [LOW] CWE-79 CVE-2022-23058: ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privi ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.
nvd
CVE-2022-23056P4LOWCVSS 3.5≥ 13.0.1, < 13.30.0v13.0.02022-06-22
CVE-2022-23056 [LOW] CWE-79 CVE-2022-23056: In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient Hi In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.
nvd
Frappe Erpnext vulnerabilities | cvebase