ERPNext SQL Injection Vulnerability Allowing Sensitive Information Disclosure

Vulnerability

A SQL injection vulnerability has been identified in ERPNext versions prior to 16.9.0. This issue allows malicious actors to exploit certain endpoints with specially crafted requests, potentially leading to the extraction of sensitive information. The vulnerability has been addressed in ERPNext version 16.9.0.

Impact

Exploitation of this vulnerability could result in unauthorized SQL injection, allowing attackers to manipulate database queries and extract sensitive information from the database.

Remediation

Users are advised to upgrade to ERPNext version 16.9.0 or later to address this vulnerability.

Added: May 13, 2026, 10:20 PM
Updated: May 13, 2026, 10:20 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
4.9
remediation
7.7
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.