CVE-2025-55732
Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injecti
Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass of the official patch released for CVE-2025-52895.
This vulnerability is fixed in 15.74.2 and 14.96.15.
HIGH · CVSS 7.5
EPSS 0.0005
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0