PT-2026-30922 · Frappé Technologies · Frappe

Hongancalif

·

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-35614

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frappe versions prior to 16.14.0 and 15.104.0
Description Frappe, a full-stack web application framework, contains a SQL injection issue in the bulk update function.
Recommendations Update to version 16.14.0 or 15.104.0.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-35614

Affected Products

Frappe