CVE-2026-32954 | Frappe ERPNext up to 15.99.x/16.7.x sql injection (GHSA-j669-ghv2-gmqg)
A vulnerability classified as critical was found in Frappe ERPNext up to 15.99.x/16.7.x. This affects an unknown part. Such manipulation leads to sql injection.
This vulnerability is listed as CVE-2026-32954. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.