Frappe Technologies
Security Scorecard
Score
87B
Total CVEs
18
Patch Rate
83%
15 patched
Avg Response
24d
days to patch
Critical Gaps
0
exploitable, no detection
Severity Breakdown
Critical0
High3
Medium14
Low0
Patch Status
Patched15 (83%)
Partial/Workaround0 (0%)
Unpatched3 (17%)
CVEs (18)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2026-23497 | Frappe Learning Management System Stored XSS | Medium | 5.4 | - | Patched |
| CVE-2025-68953 | Frappe Path Traversal Vulnerability | High | 7.5 | - | Patched |
| CVE-2025-68928 | Frappe CRM Cross-Site Scripting | Medium | 5.4 | - | Patched |
| CVE-2025-66434 | Frappe ERPNext SSTI Vulnerability | High | 8.8 | - | Patched |
| CVE-2025-66435 | Frappe ERPNext SSTI Vulnerability | Medium | 4.3 | - | Patched |
| CVE-2025-66436 | CVE-2025-66436 | Medium | 4.3 | - | Patched |
| CVE-2025-66440 | FrappiSQL | High | 8.8 | - | Patched |
| CVE-2025-67730 | Frappe Learning Management System Job Form XSS | Medium | 5.4 | - | Patched |
| CVE-2025-66581 | Frappe LMS Auth Bypass | Medium | 6.5 | - | Patched |
| CVE-2025-66206 | - | Medium | 6.8 | 14d | Patched |