frappe Vulnerabilities and Affected Products
Vulnerabilities associated with hrms.
Products
Clear product- frappe62 vulnerabilities
- lms23 vulnerabilities
- erpnext21 vulnerabilities
- Frappe Framework12 vulnerabilities
- press6 vulnerabilities
- hrms4 vulnerabilities
- crm1 vulnerability
- Frappe CRM1 vulnerability
- Frappe HelpDesk1 vulnerability
- frappe/lms1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-45081MEDIUM | Frappe HR: Permission Bypass in HRMS Leave Details APIFrappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could access other employees’ leave details due to improper authorization checks. This vulnerability is fixed in 16.5.0. CWE-863May 27, 2026 | CVSS6.5v3.1 | EPSS0.201% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-41320MEDIUM | Frappe HR has possibility of SQL Injection due to improper field sanitizationFrappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to. Versions 15.54.0 and 14.38.1 contain a patch. No known workarounds are available. CWE-89Apr 21, 2026 | CVSS6.5v3.1 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40889MEDIUM | Frappe HR has Improper Access Control on FilesFrappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthorized files by exploiting certain api endpoint. Versions 15.58.2 and 16.4.2 contain a patch. No known workarounds are available. CWE-284Apr 21, 2026 | CVSS6.5v3.1 | EPSS0.231% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40888MEDIUM | Frappe HR vulnerable to Improper Access ControlFrappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized information by exploiting certain api endpoint. Versions 15.58.1 and 16.4.1 contain a patch. No known workarounds are available. CWE-284Apr 21, 2026 | CVSS6.5v3.0 | EPSS0.232% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |