github.com
https://github.com/frappe/frappe/commit/2dab009c8b15e29aa14bcd421eee8c6b2dc0fce6 CVE-2025-58375
HIGH
Frappe has potential SQL Injection due to missing validation
Record summary
CVE-2025-58375 has a selected CVSS score of 8.1 (high).
Description
Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
frappeBrowse frappe / frappe | CVE List | < 14.96.10 | affected |
| >= 15.0.0, < 15.72.0 | affected |
References
4github.com
https://github.com/frappe/frappe/commit/ec70383ef0196d7b64fcf51b230483dac095a68b github.comConfirmation
https://github.com/frappe/frappe/security/advisories/GHSA-mggw-6xqj-rphj nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-58375