Frappe
Top 100K siteVDPActive Recognition
Program Details
Report security vulnerabilities in ERPNext and Frappe Cloud by email to [email protected]. Include a description of the issue, supporting technical details and steps to reproduce, any disclosure plans, and whether you want public recognition. Only test accounts you own may be used, and accessing or modifying other users' data is prohibited. Frappe asks for 10-15 days to confirm and respond, and for blind XSS testing to use assets you control rather than third-party sites.
Rules & Testing
Excluded Methods
DosSocial EngineeringPhishingPhysical Access
In-Scope Domains
- *.erpnext.com
- *.frappecloud.com
Out of Scope
build.erpnext.com, gateway.erpnext.com, erpnext.atlassian.net, discuss.erpnext.com, GitHub wikis, Credential or info leak in test files
Security
- Preferred Languages
- English
security.txt
- Contact
- mailto:[email protected], https://security.frappe.io
- Policy
- https://frappe.io/security
- Languages
- en
- Expires
- Dec 31, 2026