Vendorsopen-emropenemrall versions
Vulnerabilities

open-emr Openemr

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

221CVEs
CVE-2018-15146
SQL injection vulnerability in interface/de_identification_forms/find_immunization_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'search_term' parameter.
Published 2018-08-15 · Modified
8.8EPSS 0.024
CVE-2018-15147
SQL injection vulnerability in interface/forms_admin/forms_admin.php from library/registry.inc in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'id' parameter.
Published 2018-08-15 · Modified
8.8EPSS 0.024
CVE-2018-15149
SQL injection vulnerability in interface/forms/eye_mag/php/Anything_simple.php from library/forms.inc in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'encounter' parameter.
Published 2018-08-15 · Modified
8.8EPSS 0.024
CVE-2018-15150
SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'temporary_files_dir' variable in interface/super/edit_globals.php.
Published 2018-08-15 · Modified
8.8EPSS 0.024
CVE-2018-15151
SQL injection vulnerability in interface/de_identification_forms/find_code_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'search_term' parameter.
Published 2018-08-15 · Modified
8.8EPSS 0.024
CVE-2018-15148
SQL injection vulnerability in interface/patient_file/encounter/search_code.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'text' parameter.
Published 2018-08-15 · Modified
8.8EPSS 0.024
CVE-2013-10044
OpenEMR ≤ 4.1.1 SQL Injection Privilege Escalation and RCE
Published 2025-08-01 · Analyzed
8.8EPSS 0.020
CVE-2018-15144
SQL injection vulnerability in interface/de_identification_forms/find_drug_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the search_term parameter.
Published 2018-08-13 · Modified
8.8EPSS 0.018
CVE-2023-22973
A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated users to execute code via the formname parameter.
Published 2023-02-22 · Modified
8.8EPSS 0.018
CVE-2020-13566
SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability In admin/edit_group.php, when the POST parameter action is “Delete”, the POST parameter delete_group leads to a SQL injection.
Published 2021-04-13 · Modified
8.8EPSS 0.016
CVE-2021-32104
A SQL injection vulnerability exists (with user privileges) in interface/forms/eye_mag/save.php in OpenEMR 5.0.2.1.
Published 2021-05-07 · Modified
8.8EPSS 0.012
CVE-2021-32102
A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1.
Published 2021-05-07 · Modified
8.8EPSS 0.012
CVE-2019-16404
Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO statement, as demonstrated by the providerID parameter.
Published 2019-10-21 · Modified
8.8EPSS 0.011
CVE-2022-4506
Unrestricted Upload of File with Dangerous Type in openemr/openemr
Published 2022-12-15 · Modified
8.8EPSS 0.010
CVE-2026-23627
OpenEMR has SQL Injection in Immunization Search/Report
Published 2026-02-25 · Analyzed
8.8EPSS 0.008
CVE-2026-25746
OpenEMR has SQL Injection Vulnerability
Published 2026-02-25 · Analyzed
8.8EPSS 0.008
CVE-2022-2824
Authorization Bypass Through User-Controlled Key in openemr/openemr
Published 2022-08-15 · Modified
8.8EPSS 0.007
CVE-2022-4505
Authorization Bypass Through User-Controlled Key in openemr/openemr
Published 2022-12-15 · Modified
8.8EPSS 0.007
CVE-2026-29187
OpenEMR Vulnerable to Authenticated Blind Boolean-Based SQL Injection in new_search_popup.php
Published 2026-03-25 · Analyzed
8.8EPSS 0.006
CVE-2026-33910
OpenEMR has a SQL Injection Vulnerability in patient selection
Published 2026-03-25 · Analyzed
8.8EPSS 0.006
CVE-2026-33917
OpenEMR has SQL Injection in CAMOS Form
Published 2026-03-25 · Analyzed
8.8EPSS 0.006
CVE-2023-2943
Code Injection in openemr/openemr
Published 2023-05-27 · Modified
8.8EPSS 0.006
CVE-2023-2674
Improper Access Control in openemr/openemr
Published 2023-05-12 · Modified
8.8EPSS 0.006
CVE-2018-16795
OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_files.php to upload a .php file.
Published 2020-12-31 · Modified
8.8EPSS 0.006
CVE-2026-32127
SQL Injection Vulnerability in ajax graphs library (OpenEMR)
Published 2026-03-11 · Analyzed
8.8EPSS 0.006
CVE-2026-33918
OpenEMR Missing Authorization on Claim File Download Endpoint
Published 2026-03-25 · Analyzed
8.8EPSS 0.005
CVE-2025-67645
OpenEMR Vulnerable to Broken Access Control in Profile Edit Endpoint
Published 2026-01-27 · Analyzed
8.8EPSS 0.004
CVE-2026-25131
OpenEMR has Broken Access Control in Procedures Configuration
Published 2026-02-25 · Analyzed
8.8EPSS 0.003
CVE-2025-69231
OpenEMR has a Stored XSS in GAD-7 Form that Enables Session Hijacking and Privilege Escalation
Published 2026-02-25 · Analyzed
8.7EPSS 0.037
CVE-2026-33346
OpenEMR has stored XSS in portal_payment.php via Unescaped table_args
Published 2026-03-19 · Modified
8.7EPSS 0.010
CVE-2026-33348
OpenEMR has Stored XSS in patient encounter Eye Exam form $CHRONIC2 and $CHRONIC3
Published 2026-03-25 · Analyzed
8.7EPSS 0.010
CVE-2026-46518
OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics
Published 2026-06-09 · Analyzed
8.7EPSS 0.008
CVE-2023-54347
OpenEMR 7.0.1 Authentication Brute Force Mitigation Bypass
Published 2026-05-05 · Analyzed
8.7EPSS 0.005
CVE-2026-67611
OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration
Published 2026-08-03 · Analyzed
8.6EPSS 0.008
CVE-2026-39931
OpenEMR Authenticated SQL Injection via backup.php Import Feature
Published 2026-08-03 · Analyzed
8.6EPSS 0.006
CVE-2026-33299
OpenEMR has Stored XSS in patient encounter Eye Exam form answers
Published 2026-03-19 · Analyzed
8.5EPSS 0.007
CVE-2025-67491
OpenEMR has Stored XSS in ub04 helper
Published 2026-02-25 · Analyzed
8.5EPSS 0.003
CVE-2025-30161
OpenEMR Stored XSS in OpenEMR Bronchitis Form
Published 2025-03-31 · Analyzed
8.4EPSS 0.109
CVE-2023-2948
Cross-site Scripting (XSS) - Generic in openemr/openemr
Published 2023-05-28 · Modified
8.3EPSS 0.967
CVE-2023-2949
Cross-site Scripting (XSS) - Reflected in openemr/openemr
Published 2023-05-28 · Modified
8.3EPSS 0.015
← Prev2 / 6Next →