Skip to main content

Vendor archive

open-emr CVEs

Beta · best-effort

218 CVEs tagged to vendor open-emr15 Critical, 99 High, 101 Medium, 3 Low, 0 Unrated.

CVE-2021-47817

Published Jan 21, 2026

OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers can chain with a file upload to achieve remote code execution…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-10044

Published Aug 1, 2025

An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalat…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-43860

Published May 23, 2025

OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32967

Published May 23, 2025

OpenEMR is a free and open source electronic health records and medical practice management application. A logging oversight in versions prior to 7.0.3.4 allows password change ev…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32794

Published May 23, 2025

OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-22611

Published Apr 3, 2025

OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-31121

Published Apr 1, 2025

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 7.0.3.1, the Patient Image feature in OpenEMR is vulnerable to cr…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-31117

Published Mar 31, 2025

OpenEMR is a free and open source electronic health records and medical practice management application. An Out-of-Band Server-Side Request Forgery (OOB SSRF) vulnerability was id…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30161

Published Mar 31, 2025

OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vulnerability in the Bronchitis form component of OpenEMR all…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-30149

Published Mar 31, 2025

OpenEMR is a free and open source electronic health records and medical practice management application. OpenEMR allows reflected cross-site scripting (XSS) in the AJAX Script int…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-29772

Published Mar 31, 2025

OpenEMR is a free and open source electronic health records and medical practice management application. The POST parameter hidden_subcategory is output to the page without being…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-29789

Published Mar 25, 2025

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.3.0 are vulnerable to Directory Traversal in the Load…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0875

Published Nov 15, 2024

A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messa…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37734

Published Jun 26, 2024

An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-26476

Published Feb 28, 2024

An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-2949

Published May 28, 2023

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2948

Published May 28, 2023

Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2947

Published May 27, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2946

Published May 27, 2023

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2945

Published May 27, 2023

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2944

Published May 27, 2023

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2942

Published May 27, 2023

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2674

Published May 12, 2023

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 218 CVEsPage 4 of 9