20 Total CVEs
20 AI Analyzed
0 CISA KEV
4 Critical

Profile

0% ended up actively exploited 0 of 20 added to CISA KEV
20% rated critical (CVSS 9.0+) 4 critical, 16 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

18 CVEs in the last 12 months

Products

  • erpnext4
  • is3
  • Frappe2
  • CRM1
  • frappe1

5 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-20 of 20 CVEs
CVE-2026-72911
Analyzed
9.9
frappe erpnext

ERPNext contains a template injection vulnerability that allows authenticated users to execute arbitrary server-side code by manipulating template par...

2026-08-11
CVE-2026-66001
Analyzed
8.5
frappe Frappe

Frappe is a full-stack web application framework

2026-08-22
CVE-2026-65974
Analyzed
9.9
frappe erpnext

A permission boundary bypass in Frappe leads to server-side template injection and remote code execution in ERPNext due to improper handling of the fr...

2026-08-18
CVE-2026-65822
Analyzed
7.6
frappe erpnext

ERPNext is a free and open source Enterprise Resource Planning tool

2026-08-18
CVE-2026-55852
Analyzed
8.6
frappe Frappe

Frappe is a full-stack web application framework

2026-07-11
CVE-2026-55242
Analyzed
8.8
frappe erpnext

ERPNext is a free and open source Enterprise Resource Planning tool

2026-07-16
CVE-2026-53761
Analyzed
8.2
frappe CRM

Frappe CRM is an open-source customer relationship management tool. Prior to version 1.73.0, there is an authentication bypass vulnerability via logge...

2026-09-05 Patch
CVE-2026-47194
Analyzed
8.6
frappe frappe

Frappe is a full-stack web application framework

2026-08-07
CVE-2026-44447
Analyzed
8.8
frappe is

ERPNext is a free and open source Enterprise Resource Planning tool

2026-05-14
CVE-2026-44446
Analyzed
8.8
frappe is

ERPNext is a free and open source Enterprise Resource Planning tool

2026-05-14
CVE-2026-44442
Analyzed
9.9
frappe is

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks,...

2026-05-14
CVE-2025-68953
Analyzed
7.5
frappe Multiple Products

Frappe is a full-stack web application framework

2026-01-06
CVE-2025-68929
Analyzed
9
frappe Multiple Products

Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tric...

2025-12-30
CVE-2025-66205
Analyzed
7.1
frappe Multiple Products

Frappe is a full-stack web application framework

2025-12-02
CVE-2025-58439
Analyzed
8.1
frappe Multiple Products

ERP is a free and open source Enterprise Resource Planning tool

2025-09-07
CVE-2025-52044
Analyzed
7.5
frappe Multiple Products

In Frappe ERPNext v15

2025-09-17
CVE-2025-52042
Analyzed
8.2
frappe Multiple Products

In Frappe ERPNext 15

2025-10-01
CVE-2025-52041
Analyzed
8.2
frappe Multiple Products

In Frappe ERPNext 15

2025-10-01
CVE-2025-52040
Analyzed
8.2
frappe Multiple Products

In Frappe ERPNext 15

2025-10-01
CVE-2025-52039
Analyzed
8.2
frappe Multiple Products

In Frappe ERPNext 15

2025-10-01