Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 14 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe helpdesk
|
|
| CPEs | cpe:2.3:a:frappe:helpdesk:1.14.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Frappe helpdesk
|
|
| Metrics |
cvssV3_1
|
Tue, 09 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL Injections in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0. | SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0. |
| Metrics |
ssvc
|
Tue, 09 Dec 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL Injections in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0. | |
| Title | Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data | |
| First Time appeared |
Frappe
Frappe frappe Helpdesk |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:frappe:frappe_helpdesk:1.14.0:*:linux:*:*:*:*:* cpe:2.3:a:frappe:frappe_helpdesk:1.14.0:*:macos:*:*:*:*:* cpe:2.3:a:frappe:frappe_helpdesk:1.14.0:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Frappe
Frappe frappe Helpdesk |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-12-09T15:06:24.237Z
Reserved: 2025-09-17T19:31:22.120Z
Link: CVE-2025-10655
Updated: 2025-12-09T15:06:18.920Z
Status : Analyzed
Published: 2025-12-09T16:17:31.540
Modified: 2026-04-14T15:35:01.293
Link: CVE-2025-10655
No data.
OpenCVE Enrichment
No data.