Security: frappe/crm
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
-
Unauthorised disclosure of personal information due to missing validationGHSA-5wcf-p378-fmwr published
Sep 24, 2026 by shahzeelahmedModerate -
Unauthorised access to data due to missing validationGHSA-4rjw-6mxx-m345 published
Sep 8, 2026 by ps173Moderate -
Unauthorised modification of records due to missing validationGHSA-843p-qp2f-p2v8 published
Sep 8, 2026 by ps173Moderate -
Authentication Bypass via Logged Invitation Keys in crm/apiGHSA-wqrv-q8m5-qr77 published
Jun 2, 2026 by shahzeelahmedHigh -
SQL Injection vulnerability in document-linking functionalityGHSA-4q6w-fgx7-9rqx published
May 18, 2026 by shariquerikModerate -
Authorization and Privilege Escalation Issues in Frappe CRM APIsGHSA-wg3q-hf3h-58rc published
Mar 10, 2026 by ankushHigh -
Overly Permissive "All" Role PermissionsGHSA-v845-c2wq-jwg5 published
Mar 10, 2026 by ankushHigh -
Missing Authorization Checks on View Settings and Document OperationsGHSA-hfgw-j396-96v6 published
Mar 10, 2026 by ankushHigh -
Authenticated XSS via website fieldGHSA-fm34-v6j7-chwc published
Dec 29, 2025 by akhilnarangModerate
Learn more about advisories related to frappe/crm in the GitHub Advisory Database