CVE-2026-32954

HIGH

Frappe Erpnext - SQL Injection

Title source: rule

Description

ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-based and boolean-based blind SQL injection due to insufficient parameter validation, allowing attackers to infer database information. This issue has been fixed in versions 15.100.0 and 16.8.0.

Scores

CVSS v3 7.1
EPSS 0.0004
EPSS Percentile 13.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Details

CWE
CWE-89
Status published
Products (2)
frappe/erpnext < 15.100.0
frappe/erpnext >= 16.0.0-beta.1, < 16.8.0
Published Mar 20, 2026
Tracked Since Mar 20, 2026