CVE-2026-47422: Frappe
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2.
Affected products
- Frappe Frappe: before 15.107.5 (fixed in 15.107.5); from 16.0.0-beta.1, before 6.18.2 (fixed in 6.18.2)
Published 2026-07-10. Last modified 2026-07-14.