Known Vulnerabilities for Frappe Hr by Frappe
Listed below are 3 of the newest known vulnerabilities associated with "Frappe Hr" by "Frappe".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41430 json | Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-servi... | Not Provided | 2026-04-24 | 2026-04-24 |
| CVE-2026-41320 json | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially cr... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-41317 json | Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-servi... | Not Provided | 2026-04-24 | 2026-04-24 |
| CVE-2026-40889 json | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated u... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-40888 json | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticate... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-39415 json | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0, a vul... | Not Provided | 2026-04-08 | 2026-04-09 |
| CVE-2026-39351 json | Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access vi... | Not Provided | 2026-04-07 | 2026-04-09 |
| CVE-2026-35614 json | Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_update. T... | Not Provided | 2026-04-07 | 2026-04-09 |
| CVE-2026-34606 json | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to... | Not Provided | 2026-04-02 | 2026-04-03 |
| CVE-2026-31017 json | A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Fra... | Not Provided | 2026-04-08 | 2026-04-09 |