SQL Injection Vulnerability in Frappe HR Prior to Version 16.7.0
CVE-2026-54524

7.1HIGH

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54524?

Frappe HR, a popular open-source human resources management system, is susceptible to SQL injection attacks through filters in the Salary Payments report for users with the HR User role. This vulnerability arises in the report's backend code, where user-controlled input is improperly handled, enabling attackers to execute arbitrary SQL queries and extract sensitive database information. The issue has been addressed in version 16.7.0, making it crucial for users to upgrade to the latest version to safeguard their data.

Affected Version(s)

hrms < 16.7.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.