VYPR

Openemr

by Openemr

Source repositories

CVEs (229)

  • CVE-2018-15141MedAug 13, 2018
    risk 0.39cvss 6.5epss 0.14

    Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to delete arbitrary files via the "docid" parameter when the mode is set to delete.

  • CVE-2025-31121MedApr 1, 2025
    risk 0.36cvss 5.4epss 0.15

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 7.0.3.1, the Patient Image feature in OpenEMR is vulnerable to cross-site scripting attacks via the EXIF title in an image. This vulnerability is fixed in 7.0.3.1.

  • CVE-2025-30161MedMar 31, 2025
    risk 0.36cvss 5.4epss 0.10

    OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vulnerability in the Bronchitis form component of OpenEMR allows anyone who is able to edit a bronchitis form to steal credentials from administrators. This…

  • CVE-2026-33931MedMar 26, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment page allows any authenticated portal patient to access other…

  • CVE-2026-32120MedMar 25, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the fee sheet product save logic (`library/FeeSheet.class.php`) allows any authenticated…

  • CVE-2026-33304MedMar 19, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the dated reminders log allows any authenticated non-admin user to view reminder messages belonging to other users, including…

  • CVE-2026-25928MedMar 19, 2026
    risk 0.35cvss 6.5epss 0.01

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the DICOM zip/export feature uses a user-supplied destination or path component when creating the zip file, without sanitizing path traversal sequences…

  • CVE-2026-25744MedMar 19, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the encounter vitals API accepts an `id` in the request body and treats it as an UPDATE. There is no verification that the vital belongs to the current…

  • CVE-2026-25745MedMar 18, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the message/note update endpoint (e.g. PUT or POST) updates by message/note ID only and does not verify that the message belongs to the…

  • CVE-2026-32125MedMar 11, 2026
    risk 0.35cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, track/item names from the Track Anything feature are stored from user input (POST) and later rendered in Dygraph charts (titles/labels) using innerHTML or…

  • CVE-2026-32124MedMar 11, 2026
    risk 0.35cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the dynamic code picker AJAX endpoint returns code descriptions (code_text) that are rendered in the front end (e.g. DataTables) without HTML escaping. If…

  • CVE-2026-32118MedMar 11, 2026
    risk 0.35cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, stored cross-site scripting (XSS) in the Graphical Pain Map ("clickmap") form allows any authenticated clinician to inject arbitrary JavaScript that…

  • CVE-2021-47817MedJan 21, 2026
    risk 0.35cvss 5.4epss 0.01

    OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers can chain with a file upload to achieve remote code execution. Attackers can exploit the vulnerability by crafting a malicious payload to download and execute a…

  • CVE-2025-32967MedMay 23, 2025
    risk 0.35cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. A logging oversight in versions prior to 7.0.3.4 allows password change events to go unrecorded on the client-side log viewer, preventing administrators from auditing…

  • CVE-2023-22972MedFeb 22, 2023
    risk 0.35cvss 5.4epss 0.00

    A Reflected Cross-site scripting (XSS) vulnerability in interface/forms/eye_mag/php/eye_mag_functions.php in OpenEMR < 7.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the REQUEST_URI.

  • CVE-2022-24643MedMar 25, 2022
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) issue was discovered in the OpenEMR Hospital Information Management System version 6.0.0.

  • CVE-2018-1000219MedAug 20, 2018
    risk 0.35cvss 5.4epss 0.01

    OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack…

  • CVE-2018-1000218MedAug 20, 2018
    risk 0.35cvss 5.4epss 0.01

    OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack…

  • CVE-2017-1000240MedNov 17, 2017
    risk 0.35cvss 5.4epss 0.01

    The application OpenEMR is affected by multiple reflected & stored Cross-Site Scripting (XSS) vulnerabilities affecting version 5.0.0 and prior versions. These vulnerabilities could allow remote authenticated attackers to inject arbitrary web script or HTML.

  • CVE-2026-33933MedMar 26, 2026
    risk 0.33cvss 6.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to version 8.0.0.3, a reflected cross-site scripting (XSS) vulnerability in the custom template editor allows an attacker to execute…

Page 5 of 12