Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by the Frappe team in versions 15.111.0 and 16.22.0.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 29 Jul 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe
Frappe erpnext |
|
| Vendors & Products |
Frappe
Frappe erpnext |
Wed, 29 Jul 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jul 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing parameterized queries, allowing the name (docname) of a Supplier record containing SQL metacharacters to be interpreted as part of the query. Exploitation of this vulnerability could allow an authenticated user with low privileges to execute arbitrary SQL queries, bypass Frappe’s access restrictions (DocPerm), extract confidential information from the database—including fragments of the administrator’s password hash—and access other sensitive data, such as credentials, integration tokens, or financial information. | |
| Title | SQL Injection in Frappe's ERPNext | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-07-29T12:07:55.509Z
Reserved: 2026-06-22T12:58:30.777Z
Link: CVE-2026-12895
Updated: 2026-07-29T12:07:48.249Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-29T12:30:03Z