Frappe HR versions prior to 15.58.1 and 16.4.1 are vulnerable to unauthorized information access through specific API endpoints.
Claims
Frappe HR versions prior to 15.58.1 and 16.4.1 are vulnerable to unauthorized information access through specific API endpoints.
Parent: CybersecurityEntity: Frappe HRImpact: negativeDate: Apr 21, 2026Target: Frappe HR's security measures
Frappe HR versions prior to 15.54.0 and 14.38.1 are vulnerable to SQL injection attacks that could allow attackers to extract sensitive information.
Parent: CybersecurityEntity: Frappe HRImpact: negativeDate: Apr 21, 2026Target: Frappe HR's security measures
Frappe HR versions prior to 15.58.2 and 16.4.2 are vulnerable to unauthorized file access through specific API endpoints.
Parent: CybersecurityEntity: Frappe HRImpact: negativeDate: Apr 21, 2026Target: Frappe HR's security measures
Source posts
๐จ EUVD-2026-24278
๐ Score: 6.5/10 (CVSS v3.1)
๐ฆ Product: hrms, hrms
๐ข Vendor: frappe
๐
Updated: 2026-04-21
๐ Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthorized files by exploiting certain api endpoint. Versions 15.58.2 and 16.4.2 contain a patch. No known workar...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24278
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24290
๐ Score: 6.5/10 (CVSS v3.1)
๐ฆ Product: hrms, hrms
๐ข Vendor: frappe
๐
Updated: 2026-04-21
๐ Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't o...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24290
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24276
๐ Score: 6.5/10 (CVSS v3.1)
๐ฆ Product: hrms, hrms
๐ข Vendor: frappe
๐
Updated: 2026-04-21
๐ Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized information by exploiting certain api endpoint. Versions 15.58.1 and 16.4.1 contai...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24276
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability