Description
Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27054 | This CVE is a duplicate of another CVE. |
References
History
Fri, 07 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This CVE is a duplicate of another CVE. | Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0. |
| Title | Frappe has potential SQL Injection due to missing validation | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Sat, 06 Sep 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This CVE is a duplicate of another CVE. |
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-07T18:21:10.445Z
Reserved: 2025-08-29T16:19:59.012Z
Link: CVE-2025-58375
No data.
Status : Rejected
Published: 2025-09-06T00:15:35.047
Modified: 2025-09-06T00:15:35.047
Link: CVE-2025-58375
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
EUVD