Vulnerabilities
CVE-2025-68929 - Frappe may be vulnerable remote code execution due to server-side template injec...
CVE ID : CVE-2025-68929 Published : Dec. 29, 2025, 3:16 p.m. | 48 minutes ago Description : Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution. Versions 14.99.6 and 15.88.1 fix the issue. No known workarounds are available. Severity: 9.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Impact:
remote code execution
Source: Telegram CVE Monitor