Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-30214


Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure that could further lead to account takeover. Versions 14.89.0 and 15.51.0 fix the issue. There's no workaround to fix this without upgrading.


Published

2025-03-25T15:15:26.460

Last Modified

2025-08-01T15:28:15.670

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-200
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application frappe frappe < 14.89.0 Yes
Application frappe frappe < 15.51.0 Yes

References