Loading
Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. This issue affects Frappe CRM: 1.53.1.
Cite this page
CVE-2025-11461. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-11461
Use CWE-89, Frappe vendor hub and Frappe Crm product page to widen CVE-2025-11461 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-68928 for nearby disclosures in the same product family.