CVE-2025-52896: Frappe

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading to cross-site scripting (XSS). This issue has been patched in versions 14.94.2 and 15.57.0. There are no workarounds for this issue other than upgrading.

Affected products

  • Frappe Frappe: before 14.94.2 (fixed in 14.94.2); from 15.0.0, before 15.57.0 (fixed in 15.57.0)

Published 2025-06-30. Last modified 2026-06-17.