VYPR
Unrated severityNVD Advisory· Published Feb 25, 2026· Updated Feb 26, 2026

OpenEMR has SQL Injection Vulnerability

CVE-2026-25746

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 contain a SQL injection vulnerability in prescription that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the prescription listing functionality. Version 8.0.0 fixes the vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Openemr/Openemrllm-fuzzy2 versions
    <8.0.0+ 1 more
    • (no CPE)range: <8.0.0
    • (no CPE)range: < 8.0.0

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.