Loading
SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0.
Cite this page
CVE-2025-10655. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-10655
Use CWE-89, Frappe vendor hub and Helpdesk product page to widen CVE-2025-10655 into its surrounding weakness, vendor, and product context.