โ† All reports

Frappe HR versions prior to 15.58.1 and 16.4.1 are vulnerable to unauthorized information access through specific API endpoints.

CybersecurityTechnologyConflictApr 21, 2026score 0.173 posts ยท 0 replies across 1 instances
The thread discusses multiple vulnerabilities in the Frappe HR open-source HRMS system, highlighting security risks in versions prior to specific updates. These vulnerabilities include unauthorized information access and SQL injection, which could allow attackers to extract sensitive data. The updates address these issues, but the vulnerabilities underscore the importance of timely security patches.

Claims

Frappe HR versions prior to 15.58.1 and 16.4.1 are vulnerable to unauthorized information access through specific API endpoints.
Parent: CybersecurityEntity: Frappe HRImpact: negativeDate: Apr 21, 2026Target: Frappe HR's security measures
Frappe HR versions prior to 15.54.0 and 14.38.1 are vulnerable to SQL injection attacks that could allow attackers to extract sensitive information.
Parent: CybersecurityEntity: Frappe HRImpact: negativeDate: Apr 21, 2026Target: Frappe HR's security measures
Frappe HR versions prior to 15.58.2 and 16.4.2 are vulnerable to unauthorized file access through specific API endpoints.
Parent: CybersecurityEntity: Frappe HRImpact: negativeDate: Apr 21, 2026Target: Frappe HR's security measures

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24278 ๐Ÿ“Š Score: 6.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: hrms, hrms ๐Ÿข Vendor: frappe ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthorized files by exploiting certain api endpoint. Versions 15.58.2 and 16.4.2 contain a patch. No known workar... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24278 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24290 ๐Ÿ“Š Score: 6.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: hrms, hrms ๐Ÿข Vendor: frappe ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't o... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24290 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24276 ๐Ÿ“Š Score: 6.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: hrms, hrms ๐Ÿข Vendor: frappe ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized information by exploiting certain api endpoint. Versions 15.58.1 and 16.4.1 contai... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24276 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability