VYPR

Openemr

by Openemr

Source repositories

CVEs (229)

  • CVE-2019-17409MedOct 21, 2019
    risk 0.33cvss 6.1epss 0.01

    Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter.

  • CVE-2019-16862MedOct 21, 2019
    risk 0.33cvss 6.1epss 0.01

    Reflected XSS in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 allows a remote attacker to execute arbitrary code in the context of a user's session via the pid parameter.

  • CVE-2019-17179MedOct 4, 2019
    risk 0.33cvss 6.1epss 0.01

    4.1.0, 4.1.1, 4.1.2, 4.1.2.3, 4.1.2.6, 4.1.2.7, 4.2.0, 4.2.1, 4.2.2, 5.0.0, 5.0.0.5, 5.0.0.6, 5.0.1, 5.0.1.1, 5.0.1.2, 5.0.1.3, 5.0.1.4, 5.0.1.5, 5.0.1.6, 5.0.1.7, 5.0.2, fixed in version 5.0.2.1

  • CVE-2026-33909MedMar 25, 2026
    risk 0.31cvss 5.9epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, several variables in the MedEx recall/reminder processing code are concatenated directly into SQL queries without parameterization or type casting,…

  • CVE-2021-32103MedMay 7, 2021
    risk 0.31cvss 4.8epss 0.01

    A Stored XSS vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.1 allows a admin authenticated user to inject arbitrary web script or HTML via the lname parameter.

  • CVE-2026-34051MedMar 26, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper access control on the Import/Export functionality, allowing unauthorized users to perform import and export actions through direct…

  • CVE-2026-33915MedMar 26, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, five insurance company REST API routes are missing the `RestConfig::request_authorization_check()` call that every other data-modifying route in the…

  • CVE-2026-33912MedMar 25, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated attacker could craft a malicious form that, when submitted by a victim, executes arbitrary JavaScript in the victim's browser…

  • CVE-2026-33911MedMar 25, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the POST parameter `title` is reflected back in a JSON response built with `json_encode()`. Because the response is served with a `text/html`…

  • CVE-2026-33305MedMar 19, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the optional FaxSMS module (`oe-module-faxsms`) allows any authenticated OpenEMR user to invoke controller methods — including…

  • CVE-2026-33303MedMar 19, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 are vulnerable to stored cross-site scripting (XSS) via unescaped `portal_login_username` in the portal credential print view. A patient portal user…

  • CVE-2026-33299MedMar 19, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill **Eye Exam** forms in patient encounters. The answers to the form are displayed on the encounter page…

  • CVE-2026-32122MedMar 11, 2026
    risk 0.28cvss 4.3epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the Claim File Tracker feature exposes an AJAX endpoint that returns billing claim metadata (claim IDs, payer info, transmission logs). The endpoint does…

  • CVE-2022-25041MedMar 23, 2022
    risk 0.28cvss 4.3epss 0.01

    OpenEMR v6.0.0 was discovered to contain an incorrect access control issue.

  • CVE-2024-26476LowFeb 28, 2024
    risk 0.23cvss 3.5epss 0.00

    An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component.

  • CVE-2026-32119MedMar 19, 2026
    risk 0.22cvss 4.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, DOM-based stored XSS in the jQuery SearchHighlight plugin (`library/js/SearchHighlight.js`) allows an authenticated user with encounter form write access to…

  • CVE-2026-33934MedMar 26, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have a missing authorization check in `portal/sign/lib/show-signature.php` that allows any authenticated patient portal user to retrieve the drawn…

  • CVE-2023-2948MedMay 28, 2023
    risk 0.08cvss 6.1epss 0.97

    Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.

  • CVE-2022-2733MedAug 9, 2022
    risk 0.08cvss 6.1epss 0.96

    Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

  • CVE-2019-14530HigAug 13, 2019
    risk 0.08cvss 8.8epss 0.66

    An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory…

Page 6 of 12