Skip to main content

Vendor archive

open-emr CVEs

Beta · best-effort

218 CVEs tagged to vendor open-emr15 Critical, 99 High, 101 Medium, 3 Low, 0 Unrated.

CVE-2023-2566

Published May 8, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22974

Published Feb 22, 2023

A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22973

Published Feb 22, 2023

A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated users to execute code via the formname parameter.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22972

Published Feb 22, 2023

A Reflected Cross-site scripting (XSS) vulnerability in interface/forms/eye_mag/php/eye_mag_functions.php in OpenEMR < 7.0.0 allows remote authenticated users to inject arbitrary…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4733

Published Dec 27, 2022

Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4615

Published Dec 19, 2022

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4567

Published Dec 17, 2022

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4506

Published Dec 15, 2022

Unrestricted Upload of File with Dangerous Type in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4505

Published Dec 15, 2022

Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4504

Published Dec 15, 2022

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4503

Published Dec 15, 2022

Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4502

Published Dec 15, 2022

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2824

Published Aug 15, 2022

Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2734

Published Aug 9, 2022

Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2733

Published Aug 9, 2022

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2731

Published Aug 9, 2022

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2730

Published Aug 9, 2022

Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2729

Published Aug 9, 2022

Cross-site Scripting (XSS) - DOM in GitHub repository openemr/openemr prior to 7.0.0.1.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2494

Published Jul 22, 2022

Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2493

Published Jul 22, 2022

Data Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr prior to 7.0.0.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1461

Published Apr 25, 2022

Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1458

Published Apr 25, 2022

Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13567

Published Apr 18, 2022

Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this v…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 101-125 of 218 CVEsPage 5 of 9