VYPR

Mirth Connect

by NextGen

CVEs (3)

  • CVE-2023-43208CriKEVOct 26, 2023
    risk 0.91cvss 9.8epss 0.83

    NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

  • CVE-2023-37679CriAug 3, 2023
    risk 0.74cvss 9.8epss 0.99

    A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.

  • CVE-2026-82583HigSep 11, 2026
    risk 0.54cvss 8.3epss 0.00

    NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition.