Vulnerabilities > Frappe > Erpnext > High

DATE CVE VULNERABILITY TITLE RISK
2020-08-10 CVE-2020-6145 SQL Injection vulnerability in Frappe Erpnext 11.1.38
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38.
network
low complexity
frappe CWE-89
8.8
2018-12-11 CVE-2018-20061 SQL Injection vulnerability in Frappe Erpnext
A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29.
network
low complexity
frappe CWE-89
7.5