๐Ÿ” CVE Alert

CVE-2026-32954

HIGH 7.1

ERP has a possibility SQL Injection vulnerability due to missing validation

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
8th

ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-based and boolean-based blind SQL injection due to insufficient parameter validation, allowing attackers to infer database information. This issue has been fixed in versions 15.100.0 and 16.8.0.

CWE CWE-89
Vendor frappe
Product erpnext
Published Mar 20, 2026
Last Updated Mar 20, 2026
Stay Ahead of the Next One

Get instant alerts for frappe erpnext

Be the first to know when new high vulnerabilities affecting frappe erpnext are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
Low

Affected Versions

frappe / erpnext
>= 16.0.0-beta.1, < 16.8.0 < 15.100.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frappe/erpnext/security/advisories/GHSA-j669-ghv2-gmqg github.com: https://github.com/frappe/erpnext/releases/tag/v15.100.0 github.com: https://github.com/frappe/erpnext/releases/tag/v16.8.0