CVE-2026-94113

CVE-2026-94113 published: Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get...

View full NVD advisory → ← Back to CVE watch