Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
Frappe Framework: Unsecured Data Exposure Through Malicious Requests
CVE-2026-31877
Summary
Frappe Framework versions before 15.84.0 and 14.99.0 allow attackers to access sensitive information by crafting a specific type of request. This could lead to unauthorized access to data, compromising user privacy and security. Update to version 15.84.0 or 14.99.0 to fix this issue.
Original title
Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract...
Original description
Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to. This vulnerability is fixed in 15.84.0 and 14.99.0.
nvd CVSS4.0
9.3
Vulnerability type
CWE-89
SQL Injection
Published: 11 Mar 2026 · Updated: 14 Mar 2026 · First seen: 11 Mar 2026