VYPR

Vendor CVEs

Openemr

All CVEs

234 total · sorted by risk
  • CVE-2020-29140HigFeb 15, 2021
    risk 0.47cvss 7.2epss 0.02

    A SQL injection vulnerability in interface/reports/immunization_report.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code parameter.

  • CVE-2020-29139HigFeb 15, 2021
    risk 0.47cvss 7.2epss 0.02

    A SQL injection vulnerability in interface/main/finder/patient_select.php from library/patient.inc in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the searchFields parameter.

  • CVE-2020-29142HigFeb 15, 2021
    risk 0.47cvss 7.2epss 0.02

    A SQL injection vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the schedule_facility parameter when restrict_user_facility=on is in global settings.

  • CVE-2019-8371HigSep 16, 2019
    risk 0.47cvss 7.2epss 0.03

    OpenEMR v5.0.1-6 allows code execution.

  • CVE-2026-34055HigMar 26, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient notes functions in `library/pnotes.inc.php` perform updates and deletes using `WHERE id = ?` without verifying that the note…

  • CVE-2026-29187HigMar 25, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a Blind SQL Injection vulnerability exists in the Patient Search functionality (/interface/new/new_search_popup.php). The vulnerability allows an…

  • CVE-2026-33302HigMar 19, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the module ACL function `AclMain::zhAclCheck()` only checks for the presence of any "allow" (user or group). It never checks for explicit "deny"…

  • CVE-2026-33301HigMar 19, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be printed out in PDF form. An…

  • CVE-2026-32126HigMar 11, 2026
    risk 0.46cvss 7.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, an inverted boolean condition in ControllerRouter::route() causes the admin/super ACL check to be enforced only for controllers that already have their own…

  • CVE-2026-25927HigFeb 25, 2026
    risk 0.46cvss 7.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the DICOM viewer state API (e.g. upload or state save/load) accepts a document ID (`doc_id`) without verifying that the document belongs to the…

  • CVE-2021-40352MedSep 1, 2021
    risk 0.46cvss 6.5epss 0.10

    OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.

  • CVE-2020-13564MedFeb 1, 2021
    risk 0.46cvss 6.1epss 0.76

    A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGACL template acl_id parameter.

  • CVE-2020-13563MedFeb 1, 2021
    risk 0.46cvss 6.1epss 0.76

    A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGACL template group_id parameter.

  • CVE-2020-13562MedFeb 1, 2021
    risk 0.46cvss 6.1epss 0.78

    A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnaerability in the phpGACL template action parameter.

  • CVE-2019-3967MedAug 20, 2019
    risk 0.45cvss 6.5epss 0.20

    In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system.

  • CVE-2019-3964MedAug 20, 2019
    risk 0.44cvss 6.1epss 0.25

    In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.

  • CVE-2019-3963MedAug 20, 2019
    risk 0.44cvss 6.1epss 0.25

    In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.

  • CVE-2026-33913HigMar 25, 2026
    risk 0.43cvss 7.7epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted CCDA document containing `<xi:include…

  • CVE-2021-41843MedDec 17, 2021
    risk 0.43cvss 6.5epss 0.14

    An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables of the database via the parameter provider_id, as demonstrated by the /interface/main/calendar/index.php?module=PostCalendar&func=s…

  • CVE-2019-8368MedSep 16, 2019
    risk 0.43cvss 6.1epss 0.46

    OpenEMR v5.0.1-6 allows XSS.

  • CVE-2026-33932HigMar 26, 2026
    risk 0.42cvss 7.6epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-site scripting vulnerability in the CCDA document preview allows an attacker who can upload or send a CCDA document to execute…

  • CVE-2026-33918HigMar 26, 2026
    risk 0.42cvss 7.6epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-download endpoint `interface/billing/get_claim_file.php` only verifies that the caller has a valid session and CSRF token, but does…

  • CVE-2026-33321HigMar 19, 2026
    risk 0.42cvss 7.6epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be printed out in PDF form. An…

  • CVE-2026-24488MedFeb 27, 2026
    risk 0.42cvss 6.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, an arbitrary file exfiltration vulnerability in the fax sending endpoint allows any authenticated user to read and transmit any file on…

  • CVE-2026-33914HigMar 26, 2026
    risk 0.40cvss 7.2epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the PostCalendar module contains a blind SQL injection vulnerability in the `categoriesUpdate` administrative function. The `dels` POST parameter is…

  • CVE-2026-33910HigMar 25, 2026
    risk 0.40cvss 7.2epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Versions up to and including 8.0.0.2 contain a SQL injection vulnerability in the patient selection feature that can be exploited by authenticated attackers. The…

  • CVE-2020-13565MedFeb 10, 2021
    risk 0.40cvss 6.1epss 0.02

    An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request can redirect users to an arbitrary URL. An…

  • CVE-2019-3966MedAug 20, 2019
    risk 0.40cvss 6.1epss 0.02

    In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the foreign_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.

  • CVE-2019-3965MedAug 20, 2019
    risk 0.40cvss 6.1epss 0.02

    In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the document_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.

  • CVE-2018-18035MedApr 2, 2019
    risk 0.40cvss 6.1epss 0.02

    A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.

  • CVE-2018-15140MedAug 13, 2018
    risk 0.40cvss 6.5epss 0.14

    Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to read arbitrary files via the "docid" parameter when the mode is set to get.

  • CVE-2018-1000020MedFeb 9, 2018
    risk 0.40cvss 6.1epss 0.01

    OpenEMR version 5.0.0 contains a Cross Site Scripting (XSS) vulnerability in open-flash-chart.swf and _posteddata.php that can result in . This vulnerability appears to have been fixed in 5.0.0 Patch 2 or higher.

  • CVE-2017-6394MedMar 2, 2017
    risk 0.40cvss 6.1epss 0.01

    Multiple Cross-Site Scripting (XSS) issues were discovered in OpenEMR 5.0.0 and 5.0.1-dev. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to the "openemr-master/gacl/admin/object_search.php" URL (section_value; src_form). An attacker could…

  • CVE-2026-34053HigMar 26, 2026
    risk 0.39cvss 7.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the AJAX deletion endpoint `interface/forms/procedure_order/handle_deletions.php` allows any authenticated user, regardless…

  • CVE-2018-15141MedAug 13, 2018
    risk 0.39cvss 6.5epss 0.13

    Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to delete arbitrary files via the "docid" parameter when the mode is set to delete.

  • CVE-2025-31121MedApr 1, 2025
    risk 0.36cvss 5.4epss 0.17

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 7.0.3.1, the Patient Image feature in OpenEMR is vulnerable to cross-site scripting attacks via the EXIF title in an image. This vulnerability is fixed in 7.0.3.1.

  • CVE-2025-30161MedMar 31, 2025
    risk 0.36cvss 5.4epss 0.11

    OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vulnerability in the Bronchitis form component of OpenEMR allows anyone who is able to edit a bronchitis form to steal credentials from administrators. This…

  • CVE-2026-40506MedAug 17, 2026
    risk 0.35cvss 6.5epss 0.01

    OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GET parameter is passed without validation to temp_dir_cleanup(), which joins the value to the PHP temporary directory path and recursively deletes the resulting…

  • CVE-2026-33931MedMar 26, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment page allows any authenticated portal patient to access other…

  • CVE-2026-32120MedMar 25, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the fee sheet product save logic (`library/FeeSheet.class.php`) allows any authenticated…

  • CVE-2026-33304MedMar 19, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the dated reminders log allows any authenticated non-admin user to view reminder messages belonging to other users, including…

  • CVE-2026-25928MedMar 19, 2026
    risk 0.35cvss 6.5epss 0.01

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the DICOM zip/export feature uses a user-supplied destination or path component when creating the zip file, without sanitizing path traversal sequences…

  • CVE-2026-25744MedMar 19, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the encounter vitals API accepts an `id` in the request body and treats it as an UPDATE. There is no verification that the vital belongs to the current…

  • CVE-2026-25745MedMar 18, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the message/note update endpoint (e.g. PUT or POST) updates by message/note ID only and does not verify that the message belongs to the…

  • CVE-2026-32125MedMar 11, 2026
    risk 0.35cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, track/item names from the Track Anything feature are stored from user input (POST) and later rendered in Dygraph charts (titles/labels) using innerHTML or…

  • CVE-2026-32124MedMar 11, 2026
    risk 0.35cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the dynamic code picker AJAX endpoint returns code descriptions (code_text) that are rendered in the front end (e.g. DataTables) without HTML escaping. If…

  • CVE-2026-32118MedMar 11, 2026
    risk 0.35cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, stored cross-site scripting (XSS) in the Graphical Pain Map ("clickmap") form allows any authenticated clinician to inject arbitrary JavaScript that…

  • CVE-2021-47817MedJan 21, 2026
    risk 0.35cvss 5.4epss 0.01

    OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers can chain with a file upload to achieve remote code execution. Attackers can exploit the vulnerability by crafting a malicious payload to download and execute a…

  • CVE-2025-32967MedMay 23, 2025
    risk 0.35cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. A logging oversight in versions prior to 7.0.3.4 allows password change events to go unrecorded on the client-side log viewer, preventing administrators from auditing…

  • CVE-2023-22972MedFeb 22, 2023
    risk 0.35cvss 5.4epss 0.00

    A Reflected Cross-site scripting (XSS) vulnerability in interface/forms/eye_mag/php/eye_mag_functions.php in OpenEMR < 7.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the REQUEST_URI.

Page 2 of 5