Vendorsopen-emropenemrall versions
Vulnerabilities

open-emr Openemr

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

221CVEs
CVE-2022-2734
Improper Restriction of Rendered UI Layers or Frames in openemr/openemr
Published 2022-08-09 · Modified
10.0EPSS 0.008
CVE-2026-24898
OpenEMR has an Unauthenticated MedEx Token Disclosure
Published 2026-03-03 · Analyzed
10.0EPSS 0.006
CVE-2026-24848
OpenEMR Arbitrary File Write leading to Remote Code Execution
Published 2026-03-03 · Analyzed
9.9EPSS 0.065
CVE-2026-24849
OpenEMR Arbitrary File Read Vulnerability
Published 2026-02-25 · Analyzed
9.91 PoCEPSS 0.022
CVE-2026-24908
OpenEMR has SQL Injection in Patient API Sort Parameter
Published 2026-02-25 · Analyzed
9.9EPSS 0.005
CVE-2019-14529
OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
Published 2019-08-02 · Modified
9.8EPSS 0.281
CVE-2018-17179
An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php.
Published 2019-05-17 · Modified
9.8EPSS 0.128
CVE-2024-22611
OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.
Published 2025-04-03 · Analyzed
9.8EPSS 0.063
CVE-2020-13567
Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.
Published 2022-04-18 · Modified
9.8EPSS 0.023
CVE-2018-15143
Multiple SQL injection vulnerabilities in portal/find_appt_popup_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) catid or (2) providerid parameter.
Published 2018-08-13 · Modified
9.8EPSS 0.022
CVE-2018-15145
Multiple SQL injection vulnerabilities in portal/add_edit_event_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) eid, (2) userid, or (3) pid parameter.
Published 2018-08-13 · Modified
9.8EPSS 0.022
CVE-2019-17197
OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.
Published 2019-10-05 · Modified
9.8EPSS 0.015
CVE-2018-17181
An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.
Published 2019-05-17 · Modified
9.8EPSS 0.014
CVE-2024-37734
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
Published 2024-06-26 · Analyzed
9.8EPSS 0.008
CVE-2022-2733
Cross-site Scripting (XSS) - Reflected in openemr/openemr
Published 2022-08-09 · Modified
9.6EPSS 0.958
CVE-2020-13562
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnaerability in the phpGACL template action parameter.
Published 2021-02-01 · Modified
9.6EPSS 0.777
CVE-2020-13564
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGACL template acl_id parameter.
Published 2021-02-01 · Modified
9.6EPSS 0.759
CVE-2020-13563
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGACL template group_id parameter.
Published 2021-02-01 · Modified
9.6EPSS 0.759
CVE-2026-25146
OpenEMR's payments gateway_api_key secret rendered into client JS code
Published 2026-03-03 · Analyzed
9.6EPSS 0.004
CVE-2026-39932
OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection
Published 2026-08-03 · Analyzed
9.4EPSS 0.020
CVE-2018-15152
Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.php, (4) portal/get_amendments.php, (5) portal/get_lab_results.php, (6) portal/get_medications.php, (7) portal/get_patient_documents.php, (8) portal/get_problems.php, (9) portal/get_profile.php, (10) portal/portal_payment.php, (11) portal/messaging/messages.php, (12) portal/messaging/secure_chat.php, (13) portal/report/pat_ledger.php, (14) portal/report/portal_custom_report.php, or (15) portal/report/portal_patient_report.php without authenticating as a patient.
Published 2018-08-15 · Modified
9.11 PoCEPSS 0.259
CVE-2026-32238
OpenEMR has Remote Code Execution in backup functionality
Published 2026-03-19 · Modified
9.1EPSS 0.026
CVE-2020-36243
The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can send a POST request that executes arbitrary OS commands via shell metacharacters.
Published 2021-02-07 · Modified
9.0EPSS 0.641
CVE-2019-3968
In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creating a new form.
Published 2019-08-20 · Modified
9.0EPSS 0.096
CVE-2018-1000019
OpenEMR version 5.0.0 contains a OS Command Injection vulnerability in fax_dispatch.php that can result in OS command injection by an authenticated attacker with any role. This vulnerability appears to have been fixed in 5.0.0 Patch 2 or higher.
Published 2018-02-09 · Modified
9.0EPSS 0.038
CVE-2019-8371
OpenEMR v5.0.1-6 allows code execution.
Published 2019-09-16 · Modified
9.0EPSS 0.026
CVE-2026-32118
OpenEMR has Stored XSS in Graphical Pain Map legend via unescaped annotation text
Published 2026-03-11 · Analyzed
9.0EPSS 0.009
CVE-2020-19364
OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.
Published 2021-01-20 · Modified
8.8EPSS 0.706
CVE-2019-14530
An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from server.
Published 2019-08-13 · Modified
8.81 PoCEPSS 0.655
CVE-2018-15153
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/main/daemon_frame.php after modifying the "hylafax_server" global variable in interface/super/edit_globals.php.
Published 2018-08-15 · Modified
8.8EPSS 0.616
CVE-2018-9250
interface\super\edit_list.php in OpenEMR before v5_0_1_1 allows remote authenticated users to execute arbitrary SQL commands via the newlistname parameter.
Published 2018-05-18 · Modified
8.8EPSS 0.311
CVE-2020-13568
SQL injection vulnerability exists in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability in admin/edit_group.php, when the POST parameter action is “Submit”, the POST parameter parent_id leads to a SQL injection.
Published 2021-04-13 · Modified
8.8EPSS 0.297
CVE-2018-15139
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a PHP extension via the images upload form and accessing it in the images directory.
Published 2018-08-13 · Modified
8.82 PoCEPSS 0.193
CVE-2018-15142
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to execute arbitrary PHP code by writing a file with a PHP extension via the "docid" and "content" parameters and accessing it in the traversed directory.
Published 2018-08-13 · Modified
8.81 PoCEPSS 0.182
CVE-2017-9380
OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application.
Published 2017-06-02 · Modified
8.81 PoCEPSS 0.152
CVE-2018-15154
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/billing/sl_eob_search.php after modifying the "print_command" global variable in interface/super/edit_globals.php.
Published 2018-08-15 · Modified
8.8EPSS 0.102
CVE-2018-15155
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/fax_dispatch.php after modifying the "hylafax_enscript" global variable in interface/super/edit_globals.php.
Published 2018-08-15 · Modified
8.8EPSS 0.102
CVE-2018-15156
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/faxq.php after modifying the "hylafax_server" global variable in interface/super/edit_globals.php.
Published 2018-08-15 · Modified
8.8EPSS 0.102
CVE-2020-13569
A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request can lead to the execution of arbitrary requests in the context of the victim. An attacker can send an HTTP request to trigger this vulnerability.
Published 2021-01-28 · Modified
8.8EPSS 0.030
CVE-2018-10573
interface/fax/fax_dispatch.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the scan parameter.
Published 2018-04-30 · Modified
8.8EPSS 0.026
1 / 6Next →