CVE-2026-31877
EUVD-2026-1128811.03.2026, 19:16
Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to. This vulnerability is fixed in 15.84.0 and 14.99.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| frappe | frappe | 𝑥 < 14.99.0 |
| frappe | frappe | 15.0.0 ≤ 𝑥 < 15.84.0 |
𝑥
= Vulnerable software versions