SQL Injection Vulnerability in Frappe Web Application Framework
CVE-2025-55731

6.3MEDIUM

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
20 August 2025

What is CVE-2025-55731?

The Frappe web application framework is vulnerable to SQL injection, which allows attackers to craft requests that can retrieve sensitive data beyond the intended user access controls. This exposure can compromise the integrity and confidentiality of the application data. Affected versions include Frappe 15.74.2 and earlier, as well as 14.96.15 and earlier. Users are advised to update to the latest versions to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

frappe < 14.96.15 < 14.96.15

frappe >= 15.0.0, < 15.74.2 < 15.0.0, 15.74.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.