Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/ERPNext

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

CVE-2026-94113 is an information disclosure vulnerability in Frappe ERPNext affecting versions before 15.121.0 and 16.x before 16.34.0. The flaw exists in whitelisted timesheet endpoints that do not enforce doctype permissions, allowing authenticated attackers to access sensitive billable time log data without proper authorization.

Join the discussion

CVE-2026-65822 is a high-severity SQL injection vulnerability in ERPNext, an open-source ERP tool. Versions prior to 15.116.0 and between 16.0.0 and before 16.23.0 allow an authenticated user to inject malicious SQL via an unvalidated doctype filter in specific report files. This can lead to unauthorized data extraction and database query manipulation. The issue is fixed in versions 15.116.0 and 16.23.0.

Join the discussion

CVE-2026-65974 is a critical vulnerability in ERPNext, an open source ERP tool. Prior to versions 15.111.0 and 16.22.0, authenticated users with limited permissions can bypass permission boundaries due to unsafe exposure of frappe.render_template without restrict_globals. This leads to server-side template injection and remote code execution. The issue is fixed in versions 15.111.0 and 16.22.0.

Join the discussion

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render subject, body, and pdf_name fields with unrestricted globals including frappe.utils, allowing an authenticated user with a common operational role to inject template expressions, execute arbitrary server-side code, and read data across the application. This issue is fixed in versions 15.118.0 and 16.29.0.

Join the discussion

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions across erpnext/accounts/doctype/account/account.py, erpnext/accounts/doctype/process_payment_reconciliation/process_payment_reconciliation.py, erpnext/accounts/doctype/purchase_invoice/purchase_invoice.py, and erpnext/accounts/utils.py omit required write permission checks, allowing authenticated limited users to modify protected data beyond their roles. This issue is fixed in versions 15.112.0 and 16.22.0.

Join the discussion

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not apply Customer and Supplier user permissions to the Payment Ledger Entry dynamic-link party field, allowing any authenticated user to read unauthorized cross-company financial data in Accounts Receivable and Accounts Payable reports. This issue is fixed in versions 15.112.0 and 16.23.0.

Join the discussion

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WHERE clause from request-influenced posting_date and args values, allowing an authenticated low-privilege user to inject SQL and extract sensitive information. This issue is fixed in versions 15.109.0 and 16.20.0.

Join the discussion

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without enforcing Account create permission, allowing an authenticated limited user to create unauthorized accounting master records and affect financial data integrity and audit trails. This issue is fixed in versions 15.111.0 and 16.22.0.

Join the discussion

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py lacks a Process Statement Of Accounts permission check, allowing an authenticated low-privilege user to trigger automated emails outside the permitted role. This issue is fixed in versions 15.111.0 and 16.22.0.

Join the discussion

CVE-2026-13227 is a high severity improper authorization vulnerability in Frappe ERPNext. It affects versions before 15.115.0 and 16.26.0 due to insufficient access control in a whitelisted API method related to CRM prospects. This flaw could allow unauthorized users with limited privileges to access sensitive opportunity data. The vulnerability has a CVSS 4.0 base score of 7.1, indicating significant impact but no known active exploitation. No official patch or remediation guidance is currently confirmed from the vendor.

Join the discussion

Showing 1 to 10 of 25 results

Filters:Package: pkg:github/ERPNext
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses