Vendor CVEs
Openemr
All CVEs
234 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-4503 | Med | 0.00 | 6.1 | 0.01 | Dec 15, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.0.2. | ||
| CVE-2022-4502 | Med | 0.00 | 6.1 | 0.01 | Dec 15, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2. | ||
| CVE-2022-2824 | Hig | 0.00 | 8.8 | 0.01 | Aug 15, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1. | ||
| CVE-2022-2734 | Med | 0.00 | 5.4 | 0.01 | Aug 9, 2022 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1. | ||
| CVE-2022-2732 | Hig | 0.00 | 8.3 | 0.01 | Aug 9, 2022 | Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1. | ||
| CVE-2022-2731 | Med | 0.00 | 6.1 | 0.01 | Aug 9, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1. | ||
| CVE-2022-2730 | Med | 0.00 | 6.5 | 0.01 | Aug 9, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1. | ||
| CVE-2022-2729 | Med | 0.00 | 5.4 | 0.01 | Aug 9, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository openemr/openemr prior to 7.0.0.1. | ||
| CVE-2022-2494 | Med | 0.00 | 5.4 | 0.01 | Jul 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0. | ||
| CVE-2022-2493 | Hig | 0.00 | 8.1 | 0.01 | Jul 22, 2022 | Data Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr prior to 7.0.0. | ||
| CVE-2022-1461 | Med | 0.00 | 6.5 | 0.01 | Apr 25, 2022 | Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1. | ||
| CVE-2022-1459 | Hig | 0.00 | 8.3 | 0.01 | Apr 25, 2022 | Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1. | ||
| CVE-2022-1458 | Med | 0.00 | 5.4 | 0.01 | Apr 25, 2022 | Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1. | ||
| CVE-2022-1180 | Low | 0.00 | 3.5 | 0.01 | Mar 30, 2022 | Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. | ||
| CVE-2022-1177 | Med | 0.00 | 4.3 | 0.01 | Mar 30, 2022 | Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0. | ||
| CVE-2021-25923 | Hig | 0.00 | 8.1 | 0.01 | Jun 24, 2021 | In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover. | ||
| CVE-2021-25922 | Med | 0.00 | 6.1 | 0.01 | Mar 22, 2021 | In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code. | ||
| CVE-2021-25920 | Med | 0.00 | 6.5 | 0.01 | Mar 22, 2021 | In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user. | ||
| CVE-2021-25918 | Med | 0.00 | 4.8 | 0.01 | Mar 22, 2021 | In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the TOTP Authentication method page. A highly privileged attacker could inject arbitrary code into input fields when creating a… | ||
| CVE-2021-25917 | Med | 0.00 | 4.8 | 0.01 | Mar 22, 2021 | In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the U2F USB Device authentication method page. A highly privileged attacker could inject arbitrary code into input fields when… | ||
| CVE-2019-17197 | Cri | 0.00 | 9.8 | 0.01 | Oct 5, 2019 | OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc. | ||
| CVE-2018-17181 | Cri | 0.00 | 9.8 | 0.01 | May 17, 2019 | An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php. | ||
| CVE-2018-17180 | Med | 0.00 | 5.3 | 0.02 | May 17, 2019 | An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php. | ||
| CVE-2018-15151 | Hig | 0.00 | 8.8 | 0.02 | Aug 15, 2018 | SQL injection vulnerability in interface/de_identification_forms/find_code_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'search_term' parameter. | ||
| CVE-2018-15150 | Hig | 0.00 | 8.8 | 0.02 | Aug 15, 2018 | SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'temporary_files_dir' variable in… | ||
| CVE-2018-15149 | Hig | 0.00 | 8.8 | 0.02 | Aug 15, 2018 | SQL injection vulnerability in interface/forms/eye_mag/php/Anything_simple.php from library/forms.inc in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'encounter' parameter. | ||
| CVE-2018-15148 | Hig | 0.00 | 8.8 | 0.02 | Aug 15, 2018 | SQL injection vulnerability in interface/patient_file/encounter/search_code.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'text' parameter. | ||
| CVE-2018-15147 | Hig | 0.00 | 8.8 | 0.02 | Aug 15, 2018 | SQL injection vulnerability in interface/forms_admin/forms_admin.php from library/registry.inc in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'id' parameter. | ||
| CVE-2018-15146 | Hig | 0.00 | 8.8 | 0.02 | Aug 15, 2018 | SQL injection vulnerability in interface/de_identification_forms/find_immunization_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'search_term' parameter. | ||
| CVE-2018-10573 | Hig | 0.00 | 8.8 | 0.02 | Apr 30, 2018 | interface/fax/fax_dispatch.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the scan parameter. | ||
| CVE-2018-10572 | Med | 0.00 | 6.5 | 0.02 | Apr 30, 2018 | interface/patient_file/letter.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the newtemplatename and form_body parameters. | ||
| CVE-2018-10571 | Med | 0.00 | 6.1 | 0.02 | Apr 30, 2018 | Multiple reflected cross-site scripting (XSS) vulnerabilities in OpenEMR before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) patient parameter to interface/main/finder/finder_navigation.php; (2) key parameter to… | ||
| CVE-2015-4453 | 0.00 | — | 0.03 | Jul 5, 2015 | interface/globals.php in OpenEMR 2.x, 3.x, and 4.x before 4.2.0 patch 2 allows remote attackers to bypass authentication and obtain sensitive information via an ignoreAuth=1 value to certain scripts, as demonstrated by (1) interface/fax/fax_dispatch_newpid.php and (2)… | |||
| CVE-2013-4619 | 0.00 | — | 0.01 | Aug 9, 2013 | Multiple SQL injection vulnerabilities in OpenEMR 4.1.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) start or (2) end parameter to interface/reports/custom_report_range.php, or the (3) form_newid parameter to custom/chart_tracker.php. |
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.0.2.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.
- risk 0.00cvss 8.8epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
- risk 0.00cvss 5.4epss 0.01
Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1.
- risk 0.00cvss 8.3epss 0.01
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.
- risk 0.00cvss 6.5epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository openemr/openemr prior to 7.0.0.1.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.
- risk 0.00cvss 8.1epss 0.01
Data Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr prior to 7.0.0.
- risk 0.00cvss 6.5epss 0.01
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
- risk 0.00cvss 8.3epss 0.01
Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
- risk 0.00cvss 5.4epss 0.01
Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.
- risk 0.00cvss 3.5epss 0.01
Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
- risk 0.00cvss 4.3epss 0.01
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
- risk 0.00cvss 8.1epss 0.01
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.
- risk 0.00cvss 6.1epss 0.01
In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code.
- risk 0.00cvss 6.5epss 0.01
In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user.
- risk 0.00cvss 4.8epss 0.01
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the TOTP Authentication method page. A highly privileged attacker could inject arbitrary code into input fields when creating a…
- risk 0.00cvss 4.8epss 0.01
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the U2F USB Device authentication method page. A highly privileged attacker could inject arbitrary code into input fields when…
- risk 0.00cvss 9.8epss 0.01
OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.
- risk 0.00cvss 9.8epss 0.01
An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.
- risk 0.00cvss 5.3epss 0.02
An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php.
- risk 0.00cvss 8.8epss 0.02
SQL injection vulnerability in interface/de_identification_forms/find_code_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'search_term' parameter.
- risk 0.00cvss 8.8epss 0.02
SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'temporary_files_dir' variable in…
- risk 0.00cvss 8.8epss 0.02
SQL injection vulnerability in interface/forms/eye_mag/php/Anything_simple.php from library/forms.inc in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'encounter' parameter.
- risk 0.00cvss 8.8epss 0.02
SQL injection vulnerability in interface/patient_file/encounter/search_code.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'text' parameter.
- risk 0.00cvss 8.8epss 0.02
SQL injection vulnerability in interface/forms_admin/forms_admin.php from library/registry.inc in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'id' parameter.
- risk 0.00cvss 8.8epss 0.02
SQL injection vulnerability in interface/de_identification_forms/find_immunization_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'search_term' parameter.
- risk 0.00cvss 8.8epss 0.02
interface/fax/fax_dispatch.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the scan parameter.
- risk 0.00cvss 6.5epss 0.02
interface/patient_file/letter.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the newtemplatename and form_body parameters.
- risk 0.00cvss 6.1epss 0.02
Multiple reflected cross-site scripting (XSS) vulnerabilities in OpenEMR before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) patient parameter to interface/main/finder/finder_navigation.php; (2) key parameter to…
- CVE-2015-4453Jul 5, 2015risk 0.00cvss —epss 0.03
interface/globals.php in OpenEMR 2.x, 3.x, and 4.x before 4.2.0 patch 2 allows remote attackers to bypass authentication and obtain sensitive information via an ignoreAuth=1 value to certain scripts, as demonstrated by (1) interface/fax/fax_dispatch_newpid.php and (2)…
- CVE-2013-4619Aug 9, 2013risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in OpenEMR 4.1.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) start or (2) end parameter to interface/reports/custom_report_range.php, or the (3) form_newid parameter to custom/chart_tracker.php.
Page 5 of 5