
CVE-2026-31877 Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result in SQL injection, … https://www.cve.org/CVERecord?id=CVE-2026-31877
Post summary
The notice announces a SQL injection flaw in older Frappe versions, giving technical details but no evidence of exploitation or remediation.

