Frappe

4 known vulnerabilities in Frappe, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2023-51769 CVSS 6.1 medium Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
  • CVE-2026-82634 CVSS 7.1 high Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users…
  • CVE-2026-81731 CVSS 5.1 medium Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description field of the…
  • CVE-2026-66003 CVSS 7.1 high Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access control bypass in…