CVE-2026-12895 | Frappe ERPNext/Frappe up to 15.110.x/16.21.x str.format docname sql injection
A vulnerability classified as critical has been found in Frappe ERPNext and Frappe up to 15.110.x/16.21.x. This vulnerability affects the function str.format. This manipulation of the argument docname causes sql injection.
This vulnerability is registered as CVE-2026-12895. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More