CVE-2026-72908 | Frappe ERPNext up to 15.108.x/16.19.x Tax Rule tax_rule.py get_tax_template posting_date/args sql injection
A vulnerability, which was classified as critical, has been found in Frappe ERPNext up to 15.108.x/16.19.x. Affected by this issue is the function get_tax_template of the file erpnext/accounts/doctype/tax_rule/tax_rule.py of the component Tax Rule. Performing a manipulation of the argument posting_date/args results in sql injection.
This vulnerability is reported as CVE-2026-72908. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More