Frappe · Frappe Hr · CVE-2026-41320
**Name of the Vulnerable Software and Affected Versions**
Frappe HR versions prior to 15.54.0
Frappe HR versions prior to 14.38.1
**Description**
A specially crafted request sent to a specific endpoint can lead to SQL injection, a technique where malicious SQL statements are inserted into entry fields for execution, enabling an attacker to extract unauthorized information.
**Recommendations**
Update to version 15.54.0.
Update to version 14.38.1.