Vendorsopen-emropenemrany version
Vulnerabilities

open-emr Openemr any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

182CVEs
CVE-2026-25746
OpenEMR has SQL Injection Vulnerability
Published 2026-02-25 · Analyzed
8.8EPSS 0.008
CVE-2022-2824
Authorization Bypass Through User-Controlled Key in openemr/openemr
Published 2022-08-15 · Modified
8.8EPSS 0.007
CVE-2022-4505
Authorization Bypass Through User-Controlled Key in openemr/openemr
Published 2022-12-15 · Modified
8.8EPSS 0.007
CVE-2026-29187
OpenEMR Vulnerable to Authenticated Blind Boolean-Based SQL Injection in new_search_popup.php
Published 2026-03-25 · Analyzed
8.8EPSS 0.006
CVE-2026-33910
OpenEMR has a SQL Injection Vulnerability in patient selection
Published 2026-03-25 · Analyzed
8.8EPSS 0.006
CVE-2026-33917
OpenEMR has SQL Injection in CAMOS Form
Published 2026-03-25 · Analyzed
8.8EPSS 0.006
CVE-2023-2943
Code Injection in openemr/openemr
Published 2023-05-27 · Modified
8.8EPSS 0.006
CVE-2023-2674
Improper Access Control in openemr/openemr
Published 2023-05-12 · Modified
8.8EPSS 0.006
CVE-2026-32127
SQL Injection Vulnerability in ajax graphs library (OpenEMR)
Published 2026-03-11 · Analyzed
8.8EPSS 0.006
CVE-2026-33918
OpenEMR Missing Authorization on Claim File Download Endpoint
Published 2026-03-25 · Analyzed
8.8EPSS 0.005
CVE-2026-25131
OpenEMR has Broken Access Control in Procedures Configuration
Published 2026-02-25 · Analyzed
8.8EPSS 0.003
CVE-2025-69231
OpenEMR has a Stored XSS in GAD-7 Form that Enables Session Hijacking and Privilege Escalation
Published 2026-02-25 · Analyzed
8.7EPSS 0.037
CVE-2026-33346
OpenEMR has stored XSS in portal_payment.php via Unescaped table_args
Published 2026-03-19 · Modified
8.7EPSS 0.010
CVE-2026-33348
OpenEMR has Stored XSS in patient encounter Eye Exam form $CHRONIC2 and $CHRONIC3
Published 2026-03-25 · Analyzed
8.7EPSS 0.010
CVE-2026-46518
OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics
Published 2026-06-09 · Analyzed
8.7EPSS 0.008
CVE-2026-67611
OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration
Published 2026-08-03 · Analyzed
8.6EPSS 0.008
CVE-2026-39931
OpenEMR Authenticated SQL Injection via backup.php Import Feature
Published 2026-08-03 · Analyzed
8.6EPSS 0.006
CVE-2026-33299
OpenEMR has Stored XSS in patient encounter Eye Exam form answers
Published 2026-03-19 · Analyzed
8.5EPSS 0.007
CVE-2025-67491
OpenEMR has Stored XSS in ub04 helper
Published 2026-02-25 · Analyzed
8.5EPSS 0.003
CVE-2025-30161
OpenEMR Stored XSS in OpenEMR Bronchitis Form
Published 2025-03-31 · Analyzed
8.4EPSS 0.109
CVE-2023-2948
Cross-site Scripting (XSS) - Generic in openemr/openemr
Published 2023-05-28 · Modified
8.3EPSS 0.967
CVE-2023-2949
Cross-site Scripting (XSS) - Reflected in openemr/openemr
Published 2023-05-28 · Modified
8.3EPSS 0.015
CVE-2022-2493
Data Access from Outside Expected Data Manager Component in openemr/openemr
Published 2022-07-22 · Modified
8.3EPSS 0.011
CVE-2022-1459
Non-Privilege User Can View Patient’s Disclosures in openemr/openemr
Published 2022-04-25 · Modified
8.3EPSS 0.011
CVE-2022-2732
Missing Authorization in openemr/openemr
Published 2022-08-09 · Modified
8.3EPSS 0.009
CVE-2022-4615
Cross-site Scripting (XSS) - Reflected in openemr/openemr
Published 2022-12-19 · Modified
8.3EPSS 0.007
CVE-2021-25923
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.
Published 2021-06-24 · Modified
8.1EPSS 0.013
CVE-2022-1461
Non Privilege User can Enable or Disable Registered in openemr/openemr
Published 2022-04-25 · Modified
8.1EPSS 0.009
CVE-2023-2942
Improper Input Validation in openemr/openemr
Published 2023-05-27 · Modified
8.1EPSS 0.008
CVE-2017-1000241
The application OpenEMR version 5.0.0, 5.0.1-dev and prior is affected by vertical privilege escalation vulnerability. This vulnerability can allow an authenticated non-administrator users to view and modify information only accessible to administrators.
Published 2017-11-17 · Modified
8.1EPSS 0.007
CVE-2026-34053
OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler
Published 2026-03-25 · Analyzed
8.1EPSS 0.006
CVE-2022-4567
Improper Access Control in openemr/openemr
Published 2022-12-17 · Modified
8.1EPSS 0.006
CVE-2023-2950
Improper Authorization in openemr/openemr
Published 2023-05-28 · Modified
8.1EPSS 0.006
CVE-2023-2946
Improper Access Control in openemr/openemr
Published 2023-05-27 · Modified
8.1EPSS 0.005
CVE-2026-32126
OpenEMR: Inverted ACL Condition in CDR ControllerRouter Allows Any Authenticated User to Modify/Delete Clinical Rules and Plans
Published 2026-03-11 · Analyzed
8.1EPSS 0.005
CVE-2026-33301
OpenEMR has arbitrary image file read via PDF generator
Published 2026-03-19 · Analyzed
8.1EPSS 0.004
CVE-2026-33302
OpenEMR: zhAclCheck Ignores Explicit ACL Denies
Published 2026-03-19 · Analyzed
8.1EPSS 0.004
CVE-2026-34055
OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification
Published 2026-03-25 · Analyzed
8.1EPSS 0.004
CVE-2026-25164
OpenEMR's Document and Insurance REST Endpoints Skip ACL
Published 2026-02-25 · Analyzed
8.1EPSS 0.003
CVE-2026-24890
OpenEMR Portal Users Can Forge Provider Signatures
Published 2026-02-25 · Analyzed
8.1EPSS 0.002
← Prev2 / 5Next →