CVE-2025-58375: Frappe

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0.

Affected products

  • Frappe Frappe: before 14.96.10 (fixed in 14.96.10); from 15.0.0, before 15.72.0 (fixed in 15.72.0)

Published 2025-09-06. Last modified 2026-09-08.