VYPR

Vendor CVEs

Openemr

All CVEs

234 total · sorted by risk
  • CVE-2026-24848CriMar 3, 2026
    risk 0.65cvss 9.9epss 0.06

    OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and earlier, the disposeDocument() method in EtherFaxActions.php allows authenticated users to write arbitrary content to arbitrary locations on the server…

  • CVE-2024-22611CriApr 3, 2025
    risk 0.64cvss 9.8epss 0.06

    OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.

  • CVE-2020-13567CriApr 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2020-19364HigJan 20, 2021
    risk 0.63cvss 8.8epss 0.71

    OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.

  • CVE-2020-36243HigFeb 7, 2021
    risk 0.62cvss 8.8epss 0.64

    The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can send a POST request that executes arbitrary OS commands via shell metacharacters.

  • CVE-2017-9380HigJun 2, 2017
    risk 0.61cvss 8.8epss 0.15

    OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application.

  • CVE-2013-10044HigAug 1, 2025
    risk 0.60cvss 8.8epss 0.02

    An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalate privileges. Once elevated, the attacker can exploit an unrestricted file upload flaw to achieve…

  • CVE-2020-13568HigApr 13, 2021
    risk 0.60cvss 8.8epss 0.30

    SQL injection vulnerability exists in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability in admin/edit_group.php, when the POST parameter action is “Submit”, the POST parameter…

  • CVE-2026-39932CriAug 3, 2026
    risk 0.59cvss 9.1epss 0.02

    OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads into the categories…

  • CVE-2019-3968HigAug 20, 2019
    risk 0.58cvss 8.8epss 0.10

    In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creating a new form.

  • CVE-2018-1000019HigFeb 9, 2018
    risk 0.58cvss 8.8epss 0.04

    OpenEMR version 5.0.0 contains a OS Command Injection vulnerability in fax_dispatch.php that can result in OS command injection by an authenticated attacker with any role. This vulnerability appears to have been fixed in 5.0.0 Patch 2 or higher.

  • CVE-2026-32127HigMar 11, 2026
    risk 0.57cvss 8.8epss 0.01

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, OpenEMR contains a SQL injection vulnerability in the ajax graphs library that can be exploited by authenticated attackers. The vulnerability exists due to…

  • CVE-2023-22973HigFeb 22, 2023
    risk 0.57cvss 8.8epss 0.02

    A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated users to execute code via the formname parameter.

  • CVE-2021-32104HigMay 7, 2021
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists (with user privileges) in interface/forms/eye_mag/save.php in OpenEMR 5.0.2.1.

  • CVE-2021-32102HigMay 7, 2021
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1.

  • CVE-2020-13566HigApr 13, 2021
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability In admin/edit_group.php, when the POST parameter action is “Delete”, the POST parameter…

  • CVE-2020-13569HigJan 28, 2021
    risk 0.57cvss 8.8epss 0.03

    A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request can lead to the execution of arbitrary requests in the context of the…

  • CVE-2018-16795HigDec 31, 2020
    risk 0.57cvss 8.8epss 0.01

    OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_files.php to upload a .php file.

  • CVE-2019-16404HigOct 21, 2019
    risk 0.57cvss 8.8epss 0.01

    Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO statement, as demonstrated by the providerID parameter.

  • CVE-2018-15152CriAug 15, 2018
    risk 0.57cvss 9.1epss 0.26

    Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.php, (4) portal/get_amendments.php, (5)…

  • CVE-2018-15145CriAug 13, 2018
    risk 0.57cvss 9.8epss 0.02

    Multiple SQL injection vulnerabilities in portal/add_edit_event_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) eid, (2) userid, or (3) pid parameter.

  • CVE-2018-15143CriAug 13, 2018
    risk 0.57cvss 9.8epss 0.02

    Multiple SQL injection vulnerabilities in portal/find_appt_popup_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) catid or (2) providerid parameter.

  • CVE-2018-15153HigAug 15, 2018
    risk 0.55cvss 8.8epss 0.62

    OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/main/daemon_frame.php after modifying the "hylafax_server" global variable in…

  • CVE-2018-15142HigAug 13, 2018
    risk 0.55cvss 8.8epss 0.18

    Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to execute arbitrary PHP code by writing a file with a PHP extension via the "docid" and "content" parameters and accessing it in…

  • CVE-2018-15139HigAug 13, 2018
    risk 0.55cvss 8.8epss 0.19

    Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a PHP extension via the images upload form and accessing it in the images…

  • CVE-2026-67611HigAug 3, 2026
    risk 0.53cvss 8.1epss 0.01

    OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers…

  • CVE-2026-67610HigAug 3, 2026
    risk 0.53cvss 8.1epss 0.00

    OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks…

  • CVE-2022-25471HigMar 3, 2022
    risk 0.53cvss 8.1epss 0.01

    An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas via a crafted POST request to /modules/zend_modules/public/Installer/register.

  • CVE-2021-32101HigMay 7, 2021
    risk 0.53cvss 8.2epss 0.01

    The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the…

  • CVE-2017-1000241HigNov 17, 2017
    risk 0.53cvss 8.1epss 0.01

    The application OpenEMR version 5.0.0, 5.0.1-dev and prior is affected by vertical privilege escalation vulnerability. This vulnerability can allow an authenticated non-administrator users to view and modify information only accessible to administrators.

  • CVE-2026-32238CriMar 19, 2026
    risk 0.52cvss 9.1epss 0.03

    OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command injection vulnerability in the backup functionality that can be exploited by authenticated attackers. The vulnerability exists due…

  • CVE-2018-15156HigAug 15, 2018
    risk 0.51cvss 8.8epss 0.10

    OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/faxq.php after modifying the "hylafax_server" global variable in…

  • CVE-2018-15155HigAug 15, 2018
    risk 0.51cvss 8.8epss 0.10

    OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/fax_dispatch.php after modifying the "hylafax_enscript" global variable in…

  • CVE-2018-15154HigAug 15, 2018
    risk 0.51cvss 8.8epss 0.10

    OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/billing/sl_eob_search.php after modifying the "print_command" global variable in…

  • CVE-2026-46518HigJun 10, 2026
    risk 0.50cvss 7.7epss 0.01

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-site scripting vulnerability in the prescription CSS/HTML multi-print feature allows a patient portal user to execute arbitrary…

  • CVE-2026-34056HigMar 26, 2026
    risk 0.50cvss 7.7epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access Control vulnerability in OpenEMR up to and including version 8.0.0.3 allows low-privilege users to view and download Ensora eRx error logs without proper…

  • CVE-2026-33917HigMar 26, 2026
    risk 0.50cvss 8.8epss 0.01

    OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contais a SQL injection vulnerability in the ajax_save CAMOS form that can be exploited by authenticated attackers. The vulnerability exists due to…

  • CVE-2026-33348HigMar 25, 2026
    risk 0.50cvss 8.7epss 0.01

    OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form are displayed on the encounter page and in the visit…

  • CVE-2026-33346HigMar 19, 2026
    risk 0.50cvss 8.7epss 0.01

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, a stored cross-site scripting (XSS) vulnerability in the patient portal payment flow allows a patient portal user to persist arbitrary JavaScript that…

  • CVE-2026-32123HigMar 11, 2026
    risk 0.50cvss 7.7epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, sensitivity checks for group encounters are broken because the code only consults form_encounter for sensitivity, while group encounters store sensitivity…

  • CVE-2026-32121HigMar 11, 2026
    risk 0.50cvss 7.7epss 0.01

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, Stored XSS in prescription CSS/HTML print view via patient demographics. That finding involves server-side rendering of patient names via raw PHP echo.…

  • CVE-2025-43860HigMay 23, 2025
    risk 0.50cvss 7.6epss 0.14

    OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.3.4 allows any authenticated user with patient creation and editing privileges to inject arbitrary…

  • CVE-2025-32794HigMay 23, 2025
    risk 0.50cvss 7.6epss 0.10

    OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.3.4 allows any authenticated user with patient creation privileges to inject arbitrary JavaScript…

  • CVE-2018-15144HigAug 13, 2018
    risk 0.50cvss 8.8epss 0.02

    SQL injection vulnerability in interface/de_identification_forms/find_drug_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the search_term parameter.

  • CVE-2023-54347HigMay 5, 2026
    risk 0.49cvss 7.5epss 0.01

    OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protections by sending repeated login attempts to the main login endpoint. Attackers can submit POST requests with authUser and clearPass parameters to systematically…

  • CVE-2023-22974HigFeb 22, 2023
    risk 0.49cvss 7.5epss 0.02

    A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.

  • CVE-2017-16540HigNov 4, 2017
    risk 0.49cvss 7.5epss 0.01

    OpenEMR before 5.0.0 Patch 5 allows unauthenticated remote database copying because setup.php exposes functionality for cloning an existing OpenEMR site to an arbitrary attacker-controlled MySQL server via vectors involving a crafted state parameter.

  • CVE-2017-12064HigAug 1, 2017
    risk 0.49cvss 7.5epss 0.01

    The csv_log_html function in library/edihistory/edih_csv_inc.php in OpenEMR 5.0.0 and prior allows attackers to bypass intended access restrictions via a crafted name.

  • CVE-2026-39931HigAug 3, 2026
    risk 0.47cvss 7.2epss 0.01

    OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to execute arbitrary DDL and DML statements against the application database by uploading a…

  • CVE-2020-29143HigFeb 15, 2021
    risk 0.47cvss 7.2epss 0.02

    A SQL injection vulnerability in interface/reports/non_reported.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code parameter.

Page 1 of 5