VYPR

Openemr

by Openemr

Source repositories

CVEs (229)

  • CVE-2018-15144HigAug 13, 2018
    risk 0.50cvss 8.8epss 0.02

    SQL injection vulnerability in interface/de_identification_forms/find_drug_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the search_term parameter.

  • CVE-2023-54347HigMay 5, 2026
    risk 0.49cvss 7.5epss 0.01

    OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protections by sending repeated login attempts to the main login endpoint. Attackers can submit POST requests with authUser and clearPass parameters to systematically…

  • CVE-2023-22974HigFeb 22, 2023
    risk 0.49cvss 7.5epss 0.02

    A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.

  • CVE-2017-16540HigNov 4, 2017
    risk 0.49cvss 7.5epss 0.01

    OpenEMR before 5.0.0 Patch 5 allows unauthenticated remote database copying because setup.php exposes functionality for cloning an existing OpenEMR site to an arbitrary attacker-controlled MySQL server via vectors involving a crafted state parameter.

  • CVE-2017-12064HigAug 1, 2017
    risk 0.49cvss 7.5epss 0.01

    The csv_log_html function in library/edihistory/edih_csv_inc.php in OpenEMR 5.0.0 and prior allows attackers to bypass intended access restrictions via a crafted name.

  • CVE-2020-29143HigFeb 15, 2021
    risk 0.47cvss 7.2epss 0.02

    A SQL injection vulnerability in interface/reports/non_reported.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code parameter.

  • CVE-2020-29140HigFeb 15, 2021
    risk 0.47cvss 7.2epss 0.02

    A SQL injection vulnerability in interface/reports/immunization_report.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code parameter.

  • CVE-2020-29139HigFeb 15, 2021
    risk 0.47cvss 7.2epss 0.02

    A SQL injection vulnerability in interface/main/finder/patient_select.php from library/patient.inc in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the searchFields parameter.

  • CVE-2020-29142HigFeb 15, 2021
    risk 0.47cvss 7.2epss 0.02

    A SQL injection vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the schedule_facility parameter when restrict_user_facility=on is in global settings.

  • CVE-2019-8371HigSep 16, 2019
    risk 0.47cvss 7.2epss 0.03

    OpenEMR v5.0.1-6 allows code execution.

  • CVE-2026-34055HigMar 26, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient notes functions in `library/pnotes.inc.php` perform updates and deletes using `WHERE id = ?` without verifying that the note…

  • CVE-2026-29187HigMar 25, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a Blind SQL Injection vulnerability exists in the Patient Search functionality (/interface/new/new_search_popup.php). The vulnerability allows an…

  • CVE-2026-33302HigMar 19, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the module ACL function `AclMain::zhAclCheck()` only checks for the presence of any "allow" (user or group). It never checks for explicit "deny"…

  • CVE-2026-33301HigMar 19, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be printed out in PDF form. An…

  • CVE-2026-32126HigMar 11, 2026
    risk 0.46cvss 7.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, an inverted boolean condition in ControllerRouter::route() causes the admin/super ACL check to be enforced only for controllers that already have their own…

  • CVE-2026-25927HigFeb 25, 2026
    risk 0.46cvss 7.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the DICOM viewer state API (e.g. upload or state save/load) accepts a document ID (`doc_id`) without verifying that the document belongs to the…

  • CVE-2021-40352MedSep 1, 2021
    risk 0.46cvss 6.5epss 0.10

    OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.

  • CVE-2020-13564MedFeb 1, 2021
    risk 0.46cvss 6.1epss 0.76

    A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGACL template acl_id parameter.

  • CVE-2020-13563MedFeb 1, 2021
    risk 0.46cvss 6.1epss 0.76

    A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGACL template group_id parameter.

  • CVE-2020-13562MedFeb 1, 2021
    risk 0.46cvss 6.1epss 0.78

    A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnaerability in the phpGACL template action parameter.

Page 3 of 12