๐Ÿ” CVE Alert

CVE-2025-58375

HIGH 8.1

Frappe has potential SQL Injection due to missing validation

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0.

CWE CWE-89
Vendor frappe
Product frappe
Published Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for frappe frappe

Be the first to know when new high vulnerabilities affecting frappe frappe are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

frappe / frappe
< 14.96.10 >= 15.0.0, < 15.72.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frappe/frappe/security/advisories/GHSA-mggw-6xqj-rphj github.com: https://github.com/frappe/frappe/commit/2dab009c8b15e29aa14bcd421eee8c6b2dc0fce6 github.com: https://github.com/frappe/frappe/commit/ec70383ef0196d7b64fcf51b230483dac095a68b