Erpnext

Vendor:

First CVE: May 22, 2018 · Active for 8 years

59
Total CVEs
More Total CVEs than 99% of tracked products
11.8
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Erpnext over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2018
8 years ago
Most Recent CVE
May 13, 2026
76 days ago

CVE Severity & Scoring

Erpnext59 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network55 (93.2%)
Unknown3 (5.1%)
Physical0 (0.0%)
Adjacent Network1 (1.7%)
Attack Complexity
Low56 (94.9%)
High0 (0.0%)
Unknown3 (5.1%)
User Interaction
None37 (62.7%)
Unknown3 (5.1%)
Required19 (32.2%)
Privileges Required
Low23 (39.0%)
High0 (0.0%)
None33 (55.9%)
Unknown3 (5.1%)

Top CVEs

Signals from CVEs in this product scope (59 CVEs).

59 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions t
May 5, 20269.840NONO
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data
May 13, 20269.938NONO
An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
Dec 22, 20259.635NONO
Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role to execute arbitrary code by ex
May 5, 20268.834NONO
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a
Aug 22, 20226.133NOYES
ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left certain endpoints vulne
Sep 6, 20259.132NONO
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially crafted reques
May 13, 20267.531NONO
A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficien
Apr 8, 20269.131NONO
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allo
Feb 21, 20269.131NONO
An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/accounts/doctype/payment_entry/payment_entry.py is vulnerable t
Dec 15, 20258.831NONO

Exploit Exposure

Signals from CVEs in this product scope (59 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
5.1% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (59 CVEs).

Media Mentions

Signals from CVEs in this product scope (59 CVEs).

Top CNAs Publishing CVEs For Erpnext

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
16.0.119.10.2%00
16.0.019.10.3%00
15.89.019.60.4%00
15.83.219.00.3%00
15.67.036.10.3%00
15.57.597.40.3%00
14.82.118.10.8%01
14.74.318.10.8%01
13.4.018.80.6%00
13.0.013.50.8%00
12.29.016.13.2%01
11.x.x-develop_b1036e516.14.0%01
11.1.4796.10.8%00
11.1.3818.81.8%00
11.0.326.41.3%00
10.1.648.80.9%00