CVE-2026-94113 | Frappe ERPNext up to 15.120.x/16.33.x Timesheet Endpoints information disclosure
A vulnerability labeled as problematic has been found in Frappe ERPNext up to 15.120.x/16.33.x. The affected element is the function get_projectwise_timesheet_data/get_timesheet_detail_rate/get_timesheet of the component Timesheet Endpoints. Executing a manipulation can lead to information disclosure.
This vulnerability is registered as CVE-2026-94113. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.VulDB Recent EntriesRead More