CVE-2025-52040HIGH 8.2EPSS p21.3%

CVE-2025-52040CVE-2025-52040

Description

In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker can extract all information from databases by injecting a SQL query into the blanket_order_type parameter.

Scoring

CVSS 3.18.2 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
EPSS0.30% probability of exploitation · percentile 21.3% · 2026-06-19T12:03:05Z
Published2025-10-01
Last modified2025-10-03

Underlying weaknesses· 1

CWE-89

References

  1. https://github.com/Vietsunshine-Electronic-Solution-JSC/Vulnerability-Disclosures/blob/main/2025/Frappe%20Framework%20-%20Multiple%20SQL%20Injection.md
  2. https://github.com/frappe/erpnext/pull/49192/commits/1db135262d9474411ef54e3367d24bb169d2503e

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')cwe-890%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-52042
CVE
CVE-2025-52039
CVE
CVE-2025-52041
CVE
CVE-2025-66440
CVE
CVE-2025-66439
CVE
CVE-2025-11461
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.