VYPR
Vendor

Openemr

Products
3
CVEs
234
Across products
237
Status
Private

Products

3

Recent CVEs

234
View all 234 CVEs →
  • CVE-2018-17179CriMay 17, 2019
    risk 0.68cvss 9.8epss 0.13

    An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php.

  • CVE-2019-14529CriAug 2, 2019
    risk 0.66cvss 9.8epss 0.28

    OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.

  • CVE-2026-24848CriMar 3, 2026
    risk 0.65cvss 9.9epss 0.06

    OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and earlier, the disposeDocument() method in EtherFaxActions.php allows authenticated users to write arbitrary content to arbitrary locations on the server…

  • CVE-2019-14530HigAug 13, 2019
    risk 0.65cvss 8.8epss 0.66

    An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory…

  • CVE-2024-22611CriApr 3, 2025
    risk 0.64cvss 9.8epss 0.06

    OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.

  • CVE-2020-13567CriApr 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2019-17197CriOct 5, 2019
    risk 0.64cvss 9.8epss 0.01

    OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.

  • CVE-2018-17181CriMay 17, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.

  • CVE-2020-19364HigJan 20, 2021
    risk 0.63cvss 8.8epss 0.71

    OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.

  • CVE-2020-36243HigFeb 7, 2021
    risk 0.62cvss 8.8epss 0.64

    The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can send a POST request that executes arbitrary OS commands via shell metacharacters.

  • CVE-2017-9380HigJun 2, 2017
    risk 0.61cvss 8.8epss 0.15

    OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application.

  • CVE-2013-10044HigAug 1, 2025
    risk 0.60cvss 8.8epss 0.02

    An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalate privileges. Once elevated, the attacker can exploit an unrestricted file upload flaw to achieve…

  • CVE-2020-13568HigApr 13, 2021
    risk 0.60cvss 8.8epss 0.30

    SQL injection vulnerability exists in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability in admin/edit_group.php, when the POST parameter action is “Submit”, the POST parameter…

  • CVE-2018-9250HigMay 18, 2018
    risk 0.60cvss 8.8epss 0.31

    interface\super\edit_list.php in OpenEMR before v5_0_1_1 allows remote authenticated users to execute arbitrary SQL commands via the newlistname parameter.

  • CVE-2026-39932CriAug 3, 2026
    risk 0.59cvss 9.1epss 0.02

    OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads into the categories…

  • CVE-2019-3968HigAug 20, 2019
    risk 0.58cvss 8.8epss 0.10

    In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creating a new form.

  • CVE-2018-1000019HigFeb 9, 2018
    risk 0.58cvss 8.8epss 0.04

    OpenEMR version 5.0.0 contains a OS Command Injection vulnerability in fax_dispatch.php that can result in OS command injection by an authenticated attacker with any role. This vulnerability appears to have been fixed in 5.0.0 Patch 2 or higher.

  • CVE-2026-32127HigMar 11, 2026
    risk 0.57cvss 8.8epss 0.01

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, OpenEMR contains a SQL injection vulnerability in the ajax graphs library that can be exploited by authenticated attackers. The vulnerability exists due to…

  • CVE-2023-22973HigFeb 22, 2023
    risk 0.57cvss 8.8epss 0.02

    A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated users to execute code via the formname parameter.

  • CVE-2021-32104HigMay 7, 2021
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists (with user privileges) in interface/forms/eye_mag/save.php in OpenEMR 5.0.2.1.