VYPR

Vendor CVEs

Openemr

All CVEs

234 total · sorted by risk
  • CVE-2022-4503MedDec 15, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.0.2.

  • CVE-2022-4502MedDec 15, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.

  • CVE-2022-2824HigAug 15, 2022
    risk 0.00cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

  • CVE-2022-2734MedAug 9, 2022
    risk 0.00cvss 5.4epss 0.01

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1.

  • CVE-2022-2732HigAug 9, 2022
    risk 0.00cvss 8.3epss 0.01

    Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.

  • CVE-2022-2731MedAug 9, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

  • CVE-2022-2730MedAug 9, 2022
    risk 0.00cvss 6.5epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

  • CVE-2022-2729MedAug 9, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository openemr/openemr prior to 7.0.0.1.

  • CVE-2022-2494MedJul 22, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.

  • CVE-2022-2493HigJul 22, 2022
    risk 0.00cvss 8.1epss 0.01

    Data Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr prior to 7.0.0.

  • CVE-2022-1461MedApr 25, 2022
    risk 0.00cvss 6.5epss 0.01

    Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.

  • CVE-2022-1459HigApr 25, 2022
    risk 0.00cvss 8.3epss 0.01

    Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.

  • CVE-2022-1458MedApr 25, 2022
    risk 0.00cvss 5.4epss 0.01

    Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.

  • CVE-2022-1180LowMar 30, 2022
    risk 0.00cvss 3.5epss 0.01

    Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

  • CVE-2022-1177MedMar 30, 2022
    risk 0.00cvss 4.3epss 0.01

    Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.

  • CVE-2021-25923HigJun 24, 2021
    risk 0.00cvss 8.1epss 0.01

    In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.

  • CVE-2021-25922MedMar 22, 2021
    risk 0.00cvss 6.1epss 0.01

    In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code.

  • CVE-2021-25920MedMar 22, 2021
    risk 0.00cvss 6.5epss 0.01

    In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user.

  • CVE-2021-25918MedMar 22, 2021
    risk 0.00cvss 4.8epss 0.01

    In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the TOTP Authentication method page. A highly privileged attacker could inject arbitrary code into input fields when creating a…

  • CVE-2021-25917MedMar 22, 2021
    risk 0.00cvss 4.8epss 0.01

    In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the U2F USB Device authentication method page. A highly privileged attacker could inject arbitrary code into input fields when…

  • CVE-2019-17197CriOct 5, 2019
    risk 0.00cvss 9.8epss 0.01

    OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.

  • CVE-2018-17181CriMay 17, 2019
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.

  • CVE-2018-17180MedMay 17, 2019
    risk 0.00cvss 5.3epss 0.02

    An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php.

  • CVE-2018-15151HigAug 15, 2018
    risk 0.00cvss 8.8epss 0.02

    SQL injection vulnerability in interface/de_identification_forms/find_code_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'search_term' parameter.

  • CVE-2018-15150HigAug 15, 2018
    risk 0.00cvss 8.8epss 0.02

    SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'temporary_files_dir' variable in…

  • CVE-2018-15149HigAug 15, 2018
    risk 0.00cvss 8.8epss 0.02

    SQL injection vulnerability in interface/forms/eye_mag/php/Anything_simple.php from library/forms.inc in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'encounter' parameter.

  • CVE-2018-15148HigAug 15, 2018
    risk 0.00cvss 8.8epss 0.02

    SQL injection vulnerability in interface/patient_file/encounter/search_code.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'text' parameter.

  • CVE-2018-15147HigAug 15, 2018
    risk 0.00cvss 8.8epss 0.02

    SQL injection vulnerability in interface/forms_admin/forms_admin.php from library/registry.inc in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'id' parameter.

  • CVE-2018-15146HigAug 15, 2018
    risk 0.00cvss 8.8epss 0.02

    SQL injection vulnerability in interface/de_identification_forms/find_immunization_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'search_term' parameter.

  • CVE-2018-10573HigApr 30, 2018
    risk 0.00cvss 8.8epss 0.02

    interface/fax/fax_dispatch.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the scan parameter.

  • CVE-2018-10572MedApr 30, 2018
    risk 0.00cvss 6.5epss 0.02

    interface/patient_file/letter.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the newtemplatename and form_body parameters.

  • CVE-2018-10571MedApr 30, 2018
    risk 0.00cvss 6.1epss 0.02

    Multiple reflected cross-site scripting (XSS) vulnerabilities in OpenEMR before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) patient parameter to interface/main/finder/finder_navigation.php; (2) key parameter to…

  • CVE-2015-4453Jul 5, 2015
    risk 0.00cvss —epss 0.03

    interface/globals.php in OpenEMR 2.x, 3.x, and 4.x before 4.2.0 patch 2 allows remote attackers to bypass authentication and obtain sensitive information via an ignoreAuth=1 value to certain scripts, as demonstrated by (1) interface/fax/fax_dispatch_newpid.php and (2)…

  • CVE-2013-4619Aug 9, 2013
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in OpenEMR 4.1.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) start or (2) end parameter to interface/reports/custom_report_range.php, or the (3) form_newid parameter to custom/chart_tracker.php.

Page 5 of 5