CVE-2026-29081 - Frappe: Possibility of SQL Injection due to improper fieldname sanitization

CVE-2026-29081 - Frappe: Possibility of SQL Injection due to improper fieldname sanitization

CVE ID : CVE-2026-29081 Published : March 5, 2026, 9:16 p.m. | 27 minutes ago Description : Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This issue has been patched in versions 14.100.1 and 15.100.0. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
March 5, 2026
Impact: SQL injection