Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Vietsunshine

#17265of 53,625
15.6Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2025-37718
6.5
2025-09-15
Frappe · Frappe · CVE-2025-52048
**Name of the Vulnerable Software and Affected Versions** Frappe versions prior to 15.72.0 Frappe versions prior to 14.96.10 **Description** The `add tag()` function at `frappe/desk/doctype/tag/tag.py` is susceptible to SQL Injection. This allows an attacker to extract information from databases by injecting a SQL query into the `dt` parameter. **Recommendations** Update Frappe to version 15.72.0 or later. Update Frappe to version 14.96.10 or later.
PT-2025-36343
9.1
2025-09-06
Erp · Erp · CVE-2025-58439
**Name of the Vulnerable Software and Affected Versions** ERP versions prior to 14.89.2 ERP versions 15.0.0 through 15.75.1 **Description** ERP, a free and open source Enterprise Resource Planning tool, is susceptible to error-based SQL Injection due to insufficient validation of parameters. This allows retrieval of some information, such as the version. **Recommendations** Update to ERP version 14.89.2 or later. Update to ERP version 15.76.0 or later.