Vendor CVEs
Openemr
All CVEs
234 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-14529 | Cri | 0.02 | 9.8 | 0.28 | Aug 2, 2019 | OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php. | ||
| CVE-2026-25146 | Cri | 0.00 | 9.6 | 0.00 | Mar 3, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could… | ||
| CVE-2026-24898 | Cri | 0.00 | 10.0 | 0.01 | Mar 3, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx callback endpoint allows any unauthenticated visitor to obtain the practice's MedEx API tokens,… | ||
| CVE-2026-25147 | Hig | 0.00 | 7.1 | 0.00 | Feb 27, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, in `portal/portal_payment.php`, the patient id used for the page is taken from the request (`$pid = $_REQUEST['pid'] ?? $pid` and `$pid =… | ||
| CVE-2026-27943 | Med | 0.00 | 6.5 | 0.00 | Feb 26, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the eye exam (eye_mag) view loads data by `form_id` (or equivalent) without verifying that the form belongs to the current user’s… | ||
| CVE-2026-25930 | Med | 0.00 | 6.5 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Layout-Based Form (LBF) printable view accepts `formid` and `visitid` (or `patientid`) from the request and does not verify that the form belongs… | ||
| CVE-2026-25929 | Med | 0.00 | 6.5 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the document controller’s `patient_picture` context serves the patient’s photo by document ID or patient ID without verifying that the current… | ||
| CVE-2026-25746 | Hig | 0.00 | 8.8 | 0.03 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 contain a SQL injection vulnerability in prescription that can be exploited by authenticated attackers. The vulnerability exists due to insufficient… | ||
| CVE-2026-25743 | Med | 0.00 | 4.8 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, users with the "Forms administration" role can fill questionnaires ("forms") in patient encounters. The answers to the forms are displayed on the… | ||
| CVE-2026-25476 | Hig | 0.00 | 7.5 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the session expiration check in `library/auth.inc.php` runs only when `skip_timeout_reset` is not present in the request. When `skip_timeout_reset=1`… | ||
| CVE-2026-25220 | Med | 0.00 | 6.5 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Message Center accepts the URL parameter `show_all=yes` and passes it to `getPnotesByUser()`, which returns all internal messages (all users’… | ||
| CVE-2026-25164 | Hig | 0.00 | 8.1 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the REST API route table in `apis/routes/_rest_routes_standard.inc.php` does not call `RestConfig::request_authorization_check()` for the document and… | ||
| CVE-2026-24908 | Cri | 0.00 | 9.9 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vulnerability in the Patient REST API endpoint allows authenticated users with API access to execute arbitrary SQL queries through… | ||
| CVE-2026-24890 | Hig | 0.00 | 8.1 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an authorization bypass vulnerability in the patient portal signature endpoint allows authenticated portal users to upload and overwrite provider… | ||
| CVE-2026-24487 | Med | 0.00 | 6.5 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an authorization bypass vulnerability in the FHIR CareTeam resource endpoint allows patient-scoped FHIR tokens to access care team data for all… | ||
| CVE-2026-23627 | Hig | 0.00 | 8.8 | 0.01 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vulnerability in the Immunization module allows any authenticated user to execute arbitrary SQL queries, leading to complete database… | ||
| CVE-2026-25135 | Med | 0.00 | 4.5 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 have an information disclosure vulnerability that leaks the entire contact information for all users, organizations, and patients in the system to… | ||
| CVE-2026-25131 | Hig | 0.00 | 8.8 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Control vulnerability exists in the OpenEMR order types management system, allowing low-privilege users (such as Receptionist) to add… | ||
| CVE-2026-25127 | Med | 0.00 | 6.5 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the server does not properly validate user permission. Unauthorized users can view the information of authorized users. Version 8.0.0 fixes the issue. | ||
| CVE-2026-25124 | Med | 0.00 | 6.5 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the OpenEMR application is vulnerable to an access control flaw that allows low-privileged users, such as receptionists, to export the entire message… | ||
| CVE-2026-24896 | Med | 0.00 | 6.5 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Control vulnerability exists in OpenEMR’s edih_main.php endpoint, which allows any authenticated user—including low-privilege… | ||
| CVE-2026-24847 | Med | 0.00 | 6.1 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Eye Exam form module allows any authenticated user to be redirected to an arbitrary external URL. This can be exploited for phishing attacks… | ||
| CVE-2026-21443 | Med | 0.00 | 6.1 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the `xl()` translation function returns unescaped strings. While wrapper functions exist for escaping in different contexts (`xlt()` for HTML, `xla()`… | ||
| CVE-2025-69231 | Hig | 0.00 | 8.7 | 0.04 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a stored cross-site scripting vulnerability in the GAD-7 anxiety assessment form allows authenticated users with clinician privileges to inject… | ||
| CVE-2025-68277 | Med | 0.00 | 5.0 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, when a link is sent via Secure Messaging, clicking the link opens the website within the OpenEMR/Portal site. This behavior could be exploited for… | ||
| CVE-2025-67752 | Hig | 0.00 | 8.1 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default (`verify: false`), making all external… | ||
| CVE-2025-67491 | Med | 0.00 | 5.4 | 0.00 | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions 5.0.0.5 through 7.0.3.4 have a stored cross-site scripting vulnerability in the ub04 helper of the billing interface. The variable `$data` is passed in a click event… | ||
| CVE-2025-67645 | Hig | 0.00 | 8.8 | 0.00 | Jan 28, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access control in the Profile Edit endpoint. An authenticated normal user can modify the request parameters (pubpid / pid) to reference… | ||
| CVE-2025-54373 | Med | 0.00 | 6.5 | 0.00 | Jan 28, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a vulnerability where sensitive data is unintentionally revealed to unauthorized parties. Contents of Clinical Notes and Care Plan, where an… | ||
| CVE-2025-31117 | Hig | 0.00 | 7.5 | 0.00 | Mar 31, 2025 | OpenEMR is a free and open source electronic health records and medical practice management application. An Out-of-Band Server-Side Request Forgery (OOB SSRF) vulnerability was identified in OpenEMR, allowing an attacker to force the server to make unauthorized requests to… | ||
| CVE-2025-30149 | Med | 0.00 | 6.4 | 0.00 | Mar 31, 2025 | OpenEMR is a free and open source electronic health records and medical practice management application. OpenEMR allows reflected cross-site scripting (XSS) in the AJAX Script interface\super\layout_listitems_ajax.php via the target parameter. This vulnerability is fixed in… | ||
| CVE-2025-29772 | Med | 0.00 | 6.1 | 0.00 | Mar 31, 2025 | OpenEMR is a free and open source electronic health records and medical practice management application. The POST parameter hidden_subcategory is output to the page without being properly processed. This leads to a reflected cross-site scripting (XSS) vul;nerability in CAMOS… | ||
| CVE-2025-29789 | Hig | 0.00 | 7.5 | 0.01 | Mar 25, 2025 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.3.0 are vulnerable to Directory Traversal in the Load Code feature. Version 7.3.0 contains a patch for the issue. | ||
| CVE-2024-0875 | Med | 0.00 | 4.8 | 0.00 | Nov 15, 2024 | A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging feature, which can then be sent to other users. When the recipient views the malicious message,… | ||
| CVE-2024-37734 | Cri | 0.00 | 9.8 | 0.01 | Jun 26, 2024 | An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter. | ||
| CVE-2023-2950 | Hig | 0.00 | 8.1 | 0.01 | May 28, 2023 | Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-2949 | Med | 0.00 | 6.1 | 0.01 | May 28, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-2946 | Hig | 0.00 | 8.1 | 0.00 | May 27, 2023 | Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-2945 | Med | 0.00 | 5.4 | 0.00 | May 27, 2023 | Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-2944 | Med | 0.00 | 5.4 | 0.00 | May 27, 2023 | Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-2943 | Hig | 0.00 | 8.8 | 0.01 | May 27, 2023 | Code Injection in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-2942 | Hig | 0.00 | 8.1 | 0.01 | May 27, 2023 | Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-2674 | Med | 0.00 | 4.3 | 0.01 | May 12, 2023 | Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-2566 | Med | 0.00 | 4.8 | 0.01 | May 8, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2022-4733 | Med | 0.00 | 4.8 | 0.01 | Dec 27, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.2. | ||
| CVE-2022-4615 | Med | 0.00 | 6.1 | 0.01 | Dec 19, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2. | ||
| CVE-2022-4567 | Hig | 0.00 | 8.1 | 0.01 | Dec 17, 2022 | Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2. | ||
| CVE-2022-4506 | Hig | 0.00 | 8.8 | 0.01 | Dec 15, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository openemr/openemr prior to 7.0.0.2. | ||
| CVE-2022-4505 | Hig | 0.00 | 8.8 | 0.01 | Dec 15, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2. | ||
| CVE-2022-4504 | Hig | 0.00 | 7.5 | 0.01 | Dec 15, 2022 | Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2. |
- risk 0.02cvss 9.8epss 0.28
OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
- risk 0.00cvss 9.6epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could…
- risk 0.00cvss 10.0epss 0.01
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx callback endpoint allows any unauthenticated visitor to obtain the practice's MedEx API tokens,…
- risk 0.00cvss 7.1epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, in `portal/portal_payment.php`, the patient id used for the page is taken from the request (`$pid = $_REQUEST['pid'] ?? $pid` and `$pid =…
- risk 0.00cvss 6.5epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the eye exam (eye_mag) view loads data by `form_id` (or equivalent) without verifying that the form belongs to the current user’s…
- risk 0.00cvss 6.5epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Layout-Based Form (LBF) printable view accepts `formid` and `visitid` (or `patientid`) from the request and does not verify that the form belongs…
- risk 0.00cvss 6.5epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the document controller’s `patient_picture` context serves the patient’s photo by document ID or patient ID without verifying that the current…
- risk 0.00cvss 8.8epss 0.03
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 contain a SQL injection vulnerability in prescription that can be exploited by authenticated attackers. The vulnerability exists due to insufficient…
- risk 0.00cvss 4.8epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, users with the "Forms administration" role can fill questionnaires ("forms") in patient encounters. The answers to the forms are displayed on the…
- risk 0.00cvss 7.5epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the session expiration check in `library/auth.inc.php` runs only when `skip_timeout_reset` is not present in the request. When `skip_timeout_reset=1`…
- risk 0.00cvss 6.5epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Message Center accepts the URL parameter `show_all=yes` and passes it to `getPnotesByUser()`, which returns all internal messages (all users’…
- risk 0.00cvss 8.1epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the REST API route table in `apis/routes/_rest_routes_standard.inc.php` does not call `RestConfig::request_authorization_check()` for the document and…
- risk 0.00cvss 9.9epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vulnerability in the Patient REST API endpoint allows authenticated users with API access to execute arbitrary SQL queries through…
- risk 0.00cvss 8.1epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an authorization bypass vulnerability in the patient portal signature endpoint allows authenticated portal users to upload and overwrite provider…
- risk 0.00cvss 6.5epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an authorization bypass vulnerability in the FHIR CareTeam resource endpoint allows patient-scoped FHIR tokens to access care team data for all…
- risk 0.00cvss 8.8epss 0.01
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vulnerability in the Immunization module allows any authenticated user to execute arbitrary SQL queries, leading to complete database…
- risk 0.00cvss 4.5epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 have an information disclosure vulnerability that leaks the entire contact information for all users, organizations, and patients in the system to…
- risk 0.00cvss 8.8epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Control vulnerability exists in the OpenEMR order types management system, allowing low-privilege users (such as Receptionist) to add…
- risk 0.00cvss 6.5epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the server does not properly validate user permission. Unauthorized users can view the information of authorized users. Version 8.0.0 fixes the issue.
- risk 0.00cvss 6.5epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the OpenEMR application is vulnerable to an access control flaw that allows low-privileged users, such as receptionists, to export the entire message…
- risk 0.00cvss 6.5epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Control vulnerability exists in OpenEMR’s edih_main.php endpoint, which allows any authenticated user—including low-privilege…
- risk 0.00cvss 6.1epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Eye Exam form module allows any authenticated user to be redirected to an arbitrary external URL. This can be exploited for phishing attacks…
- risk 0.00cvss 6.1epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the `xl()` translation function returns unescaped strings. While wrapper functions exist for escaping in different contexts (`xlt()` for HTML, `xla()`…
- risk 0.00cvss 8.7epss 0.04
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a stored cross-site scripting vulnerability in the GAD-7 anxiety assessment form allows authenticated users with clinician privileges to inject…
- risk 0.00cvss 5.0epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, when a link is sent via Secure Messaging, clicking the link opens the website within the OpenEMR/Portal site. This behavior could be exploited for…
- risk 0.00cvss 8.1epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default (`verify: false`), making all external…
- risk 0.00cvss 5.4epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Versions 5.0.0.5 through 7.0.3.4 have a stored cross-site scripting vulnerability in the ub04 helper of the billing interface. The variable `$data` is passed in a click event…
- risk 0.00cvss 8.8epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access control in the Profile Edit endpoint. An authenticated normal user can modify the request parameters (pubpid / pid) to reference…
- risk 0.00cvss 6.5epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a vulnerability where sensitive data is unintentionally revealed to unauthorized parties. Contents of Clinical Notes and Care Plan, where an…
- risk 0.00cvss 7.5epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. An Out-of-Band Server-Side Request Forgery (OOB SSRF) vulnerability was identified in OpenEMR, allowing an attacker to force the server to make unauthorized requests to…
- risk 0.00cvss 6.4epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. OpenEMR allows reflected cross-site scripting (XSS) in the AJAX Script interface\super\layout_listitems_ajax.php via the target parameter. This vulnerability is fixed in…
- risk 0.00cvss 6.1epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. The POST parameter hidden_subcategory is output to the page without being properly processed. This leads to a reflected cross-site scripting (XSS) vul;nerability in CAMOS…
- risk 0.00cvss 7.5epss 0.01
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.3.0 are vulnerable to Directory Traversal in the Load Code feature. Version 7.3.0 contains a patch for the issue.
- risk 0.00cvss 4.8epss 0.00
A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging feature, which can then be sent to other users. When the recipient views the malicious message,…
- risk 0.00cvss 9.8epss 0.01
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
- risk 0.00cvss 8.1epss 0.01
Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 8.1epss 0.00
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 5.4epss 0.00
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 5.4epss 0.00
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 8.8epss 0.01
Code Injection in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 8.1epss 0.01
Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 4.3epss 0.01
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 4.8epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 4.8epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.2.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.
- risk 0.00cvss 8.1epss 0.01
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2.
- risk 0.00cvss 8.8epss 0.01
Unrestricted Upload of File with Dangerous Type in GitHub repository openemr/openemr prior to 7.0.0.2.
- risk 0.00cvss 8.8epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.
- risk 0.00cvss 7.5epss 0.01
Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2.
Page 4 of 5