CVE-2026-39352EPSS p68.6%
CVE-2026-39352CVE-2026-39352
Description
Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Path Traversal. The issue is resolved in versions 16.15.0, 15.105.0 and above.
Scoring
| EPSS | 1.26% probability of exploitation · percentile 68.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-23 |