CVE-2025-52048: Frappe
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py` is vulnerable to SQL Injection, which allows an attacker to extract information from databases by injecting a SQL query into the `dt` parameter.
Affected products
- Frappe Frappe: from 14.0.0, before 14.96.10 (fixed in 14.96.10); from 15.0.0, before 15.72.0 (fixed in 15.72.0)
Published 2025-09-15. Last modified 2026-06-17.