Frappe vulnerabilities
3 CVEs tracked
In our reporting, Frappe appears in the context of SQL injection risks specifically within its ERPNext product. A second key event involves unrestricted access to the Document Follow API for authenticated users. The primary vulnerability to focus on is CVE-2026-12895, where SQL injection is possible in ERPNext via a Supplier record's name; defenders should also review permission checks on the update_follow functionality related to CVE-2026-66058.
This vendor's CVEs3
This hub is built from skopnix's own reporting on Frappe: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.