VYPR

Vendor CVEs

Openemr

All CVEs

234 total · sorted by risk
  • CVE-2022-24643MedMar 25, 2022
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) issue was discovered in the OpenEMR Hospital Information Management System version 6.0.0.

  • CVE-2018-1000219MedAug 20, 2018
    risk 0.35cvss 5.4epss 0.01

    OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack…

  • CVE-2018-1000218MedAug 20, 2018
    risk 0.35cvss 5.4epss 0.01

    OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack…

  • CVE-2017-1000240MedNov 17, 2017
    risk 0.35cvss 5.4epss 0.01

    The application OpenEMR is affected by multiple reflected & stored Cross-Site Scripting (XSS) vulnerabilities affecting version 5.0.0 and prior versions. These vulnerabilities could allow remote authenticated attackers to inject arbitrary web script or HTML.

  • CVE-2026-40507MedAug 19, 2026
    risk 0.33cvss 6.1epss 0.00

    OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handler. The templateHtml GET parameter is reflected into the page response without sanitization. An attacker can craft a URL that executes arbitrary JavaScript in…

  • CVE-2026-33933MedMar 26, 2026
    risk 0.33cvss 6.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to version 8.0.0.3, a reflected cross-site scripting (XSS) vulnerability in the custom template editor allows an attacker to execute…

  • CVE-2019-17409MedOct 21, 2019
    risk 0.33cvss 6.1epss 0.01

    Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter.

  • CVE-2019-16862MedOct 21, 2019
    risk 0.33cvss 6.1epss 0.01

    Reflected XSS in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 allows a remote attacker to execute arbitrary code in the context of a user's session via the pid parameter.

  • CVE-2019-17179MedOct 4, 2019
    risk 0.33cvss 6.1epss 0.01

    4.1.0, 4.1.1, 4.1.2, 4.1.2.3, 4.1.2.6, 4.1.2.7, 4.2.0, 4.2.1, 4.2.2, 5.0.0, 5.0.0.5, 5.0.0.6, 5.0.1, 5.0.1.1, 5.0.1.2, 5.0.1.3, 5.0.1.4, 5.0.1.5, 5.0.1.6, 5.0.1.7, 5.0.2, fixed in version 5.0.2.1

  • CVE-2026-67612MedAug 3, 2026
    risk 0.31cvss 4.8epss 0.00

    OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that allows authenticated administrators to inject arbitrary HTML and JavaScript by storing malicious payloads through the template save mode, which only filters…

  • CVE-2026-33909MedMar 25, 2026
    risk 0.31cvss 5.9epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, several variables in the MedEx recall/reminder processing code are concatenated directly into SQL queries without parameterization or type casting,…

  • CVE-2021-32103MedMay 7, 2021
    risk 0.31cvss 4.8epss 0.01

    A Stored XSS vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.1 allows a admin authenticated user to inject arbitrary web script or HTML via the lname parameter.

  • CVE-2026-40508MedAug 19, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated attackers with Forms Administration permissions to upload template files containing arbitrary HTML or JavaScript. Attackers can…

  • CVE-2026-34051MedMar 26, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper access control on the Import/Export functionality, allowing unauthorized users to perform import and export actions through direct…

  • CVE-2026-33915MedMar 26, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, five insurance company REST API routes are missing the `RestConfig::request_authorization_check()` call that every other data-modifying route in the…

  • CVE-2026-33912MedMar 25, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated attacker could craft a malicious form that, when submitted by a victim, executes arbitrary JavaScript in the victim's browser…

  • CVE-2026-33911MedMar 25, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the POST parameter `title` is reflected back in a JSON response built with `json_encode()`. Because the response is served with a `text/html`…

  • CVE-2026-33305MedMar 19, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the optional FaxSMS module (`oe-module-faxsms`) allows any authenticated OpenEMR user to invoke controller methods — including…

  • CVE-2026-33303MedMar 19, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 are vulnerable to stored cross-site scripting (XSS) via unescaped `portal_login_username` in the portal credential print view. A patient portal user…

  • CVE-2026-33299MedMar 19, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill **Eye Exam** forms in patient encounters. The answers to the form are displayed on the encounter page…

  • CVE-2026-32122MedMar 11, 2026
    risk 0.28cvss 4.3epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the Claim File Tracker feature exposes an AJAX endpoint that returns billing claim metadata (claim IDs, payer info, transmission logs). The endpoint does…

  • CVE-2022-25041MedMar 23, 2022
    risk 0.28cvss 4.3epss 0.01

    OpenEMR v6.0.0 was discovered to contain an incorrect access control issue.

  • CVE-2024-26476LowFeb 28, 2024
    risk 0.23cvss 3.5epss 0.00

    An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component.

  • CVE-2026-32119MedMar 19, 2026
    risk 0.22cvss 4.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, DOM-based stored XSS in the jQuery SearchHighlight plugin (`library/js/SearchHighlight.js`) allows an authenticated user with encounter form write access to…

  • CVE-2026-76614MedAug 19, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel POST parameter is passed to the archive restore handler without sanitization for path traversal sequences. The handler checks whether the supplied path exists on…

  • CVE-2026-40509MedAug 19, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter in the DICOM viewer page is embedded unsanitized as a URL without validation against expected path formats. An attacker can craft a URL that causes an…

  • CVE-2026-33934MedMar 26, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have a missing authorization check in `portal/sign/lib/show-signature.php` that allows any authenticated patient portal user to retrieve the drawn…

  • CVE-2023-2948MedMay 28, 2023
    risk 0.08cvss 6.1epss 0.97

    Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.

  • CVE-2022-2733MedAug 9, 2022
    risk 0.08cvss 6.1epss 0.96

    Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

  • CVE-2019-14530HigAug 13, 2019
    risk 0.08cvss 8.8epss 0.66

    An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory…

  • CVE-2023-2947MedMay 27, 2023
    risk 0.07cvss 4.8epss 0.90

    Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.

  • CVE-2021-25921MedMar 22, 2021
    risk 0.07cvss 5.4epss 0.91

    In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker could lure an admin to enter a malicious payload and by that initiate the exploit.

  • CVE-2022-1179MedMar 30, 2022
    risk 0.06cvss 5.4epss 0.77

    Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

  • CVE-2021-25919MedMar 22, 2021
    risk 0.06cvss 4.8epss 0.70

    In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.

  • CVE-2022-1181MedMar 30, 2022
    risk 0.04cvss 5.4epss 0.51

    Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2.

  • CVE-2022-1178MedMar 30, 2022
    risk 0.04cvss 5.4epss 0.52

    Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

  • CVE-2018-17179CriMay 17, 2019
    risk 0.04cvss 9.8epss 0.12

    An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php.

  • CVE-2012-0991Feb 7, 2012
    risk 0.04cvss —epss 0.11

    Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the formname parameter to (1) contrib/acog/print_form.php; or (2) load_form.php, (3) view_form.php, or (4) trend_form.php in…

  • CVE-2007-0649Feb 1, 2007
    risk 0.04cvss —epss 0.06

    Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the srcdir parameter in…

  • CVE-2026-24849CriFeb 25, 2026
    risk 0.03cvss 9.9epss 0.02

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument()` method in `EtherFaxActions.php` allows authenticated users to read arbitrary files from the server filesystem. Any…

  • CVE-2018-9250HigMay 18, 2018
    risk 0.03cvss 8.8epss 0.29

    interface\super\edit_list.php in OpenEMR before v5_0_1_1 allows remote authenticated users to execute arbitrary SQL commands via the newlistname parameter.

  • CVE-2014-5462Dec 8, 2014
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in OpenEMR 4.1.2 (Patch 7) and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) layout_id parameter to interface/super/edit_layout.php; (2) form_patient_id, (3) form_drug_name, or (4) form_lot_number…

  • CVE-2013-4620Aug 9, 2013
    risk 0.03cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in interface/main/onotes/office_comments_full.php in OpenEMR 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the note parameter.

  • CVE-2012-2115Sep 9, 2012
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in interface/login/validateUser.php in OpenEMR 4.1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the u parameter.

  • CVE-2011-5161Sep 9, 2012
    risk 0.03cvss —epss 0.02

    Unrestricted file upload vulnerability in the patient photograph functionality in OpenEMR 4 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the patient…

  • CVE-2011-5160Sep 9, 2012
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in setup.php in OpenEMR 4 allows remote attackers to inject arbitrary web script or HTML via the site parameter.

  • CVE-2012-0992Feb 7, 2012
    risk 0.03cvss —epss 0.04

    interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file parameter.

  • CVE-2006-5811Nov 8, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in library/translation.inc.php in OpenEMR 2.8.1, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[srcdir] parameter.

  • CVE-2006-5795Nov 8, 2006
    risk 0.03cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the srcdir parameter to (a) billing_process.php, (b) billing_report.php, (c)…

  • CVE-2006-2929Jun 9, 2006
    risk 0.03cvss —epss 0.06

    PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fileroot] parameter.