CVE-2025-68929CRITICAL 9.0EPSS p33.3%

CVE-2025-68929CVE-2025-68929

Description

Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution. Versions 14.99.6 and 15.88.1 fix the issue. No known workarounds are available.

Scoring

CVSS 3.19.0 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
EPSS0.42% probability of exploitation · percentile 33.3% · 2026-06-19T12:03:05Z
Published2025-12-29
Last modified2025-12-31

Underlying weaknesses· 1

CWE-1336

References

  1. https://github.com/frappe/frappe/releases/tag/v14.99.6
  2. https://github.com/frappe/frappe/releases/tag/v15.88.1
  3. https://github.com/frappe/frappe/security/advisories/GHSA-qq98-vfv9-xmxh

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements Used in a Template Enginecwe-13360%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-30213
CVE
CVE-2025-55731
CVE
CVE-2026-29081
CVE
CVE-2025-52898
CVE
CVE-2026-31877
CVE
CVE-2025-66205
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.