SQL Injection Vulnerability in ERPNext by Frappe
CVE-2026-44447
8.8HIGH
What is CVE-2026-44447?
ERPNext, an open-source Enterprise Resource Planning tool developed by Frappe, contained a vulnerability allowing SQL injection via specially crafted requests. This flaw could enable attackers to access sensitive data within the system. Users are strongly urged to update to version 16.9.0 or later to mitigate this risk and enhance their application's security.
Affected Version(s)
erpnext < 16.9.0
