CVE-2025-55732

Severity CVSS v4.0:
HIGH
Type:
CWE-89 SQL Injection
Publication date:
20/08/2025
Last modified:
22/08/2025

Description

Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass of the official patch released for CVE-2025-52895. This vulnerability is fixed in 15.74.2 and 14.96.15.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:* 14.96.15 (excluding)
cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:* 15.0.0 (including) 15.74.2 (excluding)