Vendorsopen-emropenemrall versions
Vulnerabilities

open-emr Openemr

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

221CVEs
CVE-2022-2493
Data Access from Outside Expected Data Manager Component in openemr/openemr
Published 2022-07-22 · Modified
8.3EPSS 0.011
CVE-2022-1459
Non-Privilege User Can View Patient’s Disclosures in openemr/openemr
Published 2022-04-25 · Modified
8.3EPSS 0.011
CVE-2022-2732
Missing Authorization in openemr/openemr
Published 2022-08-09 · Modified
8.3EPSS 0.009
CVE-2022-4615
Cross-site Scripting (XSS) - Reflected in openemr/openemr
Published 2022-12-19 · Modified
8.3EPSS 0.007
CVE-2021-32101
The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the attacker can then manipulate and read data of every registered patient.
Published 2021-05-07 · Modified
8.2EPSS 0.012
CVE-2021-25923
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.
Published 2021-06-24 · Modified
8.1EPSS 0.013
CVE-2022-1461
Non Privilege User can Enable or Disable Registered in openemr/openemr
Published 2022-04-25 · Modified
8.1EPSS 0.009
CVE-2022-25471
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas via a crafted POST request to /modules/zend_modules/public/Installer/register.
Published 2022-03-02 · Modified
8.1EPSS 0.008
CVE-2023-2942
Improper Input Validation in openemr/openemr
Published 2023-05-27 · Modified
8.1EPSS 0.008
CVE-2017-1000241
The application OpenEMR version 5.0.0, 5.0.1-dev and prior is affected by vertical privilege escalation vulnerability. This vulnerability can allow an authenticated non-administrator users to view and modify information only accessible to administrators.
Published 2017-11-17 · Modified
8.1EPSS 0.007
CVE-2026-34053
OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler
Published 2026-03-25 · Analyzed
8.1EPSS 0.006
CVE-2022-4567
Improper Access Control in openemr/openemr
Published 2022-12-17 · Modified
8.1EPSS 0.006
CVE-2023-2950
Improper Authorization in openemr/openemr
Published 2023-05-28 · Modified
8.1EPSS 0.006
CVE-2023-2946
Improper Access Control in openemr/openemr
Published 2023-05-27 · Modified
8.1EPSS 0.005
CVE-2026-32126
OpenEMR: Inverted ACL Condition in CDR ControllerRouter Allows Any Authenticated User to Modify/Delete Clinical Rules and Plans
Published 2026-03-11 · Analyzed
8.1EPSS 0.005
CVE-2026-33301
OpenEMR has arbitrary image file read via PDF generator
Published 2026-03-19 · Analyzed
8.1EPSS 0.004
CVE-2024-0875
Stored XSS in openemr/openemr
Published 2024-11-15 · Analyzed
8.1EPSS 0.004
CVE-2026-33302
OpenEMR: zhAclCheck Ignores Explicit ACL Denies
Published 2026-03-19 · Analyzed
8.1EPSS 0.004
CVE-2026-34055
OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification
Published 2026-03-25 · Analyzed
8.1EPSS 0.004
CVE-2026-25164
OpenEMR's Document and Insurance REST Endpoints Skip ACL
Published 2026-02-25 · Analyzed
8.1EPSS 0.003
CVE-2026-24890
OpenEMR Portal Users Can Forge Provider Signatures
Published 2026-02-25 · Analyzed
8.1EPSS 0.002
CVE-2025-67752
OpenEMR Has Disabled SSL Certificate Verification in HTTP Client
Published 2026-02-25 · Analyzed
8.1EPSS 0.002
CVE-2022-1181
Stored Cross Site Scripting in openemr/openemr
Published 2022-03-30 · Modified
8.0EPSS 0.515
CVE-2026-32121
OpenEMR: Stored DOM XSS via `.html()` in Portal Signer Modal
Published 2026-03-11 · Analyzed
7.7EPSS 0.006
CVE-2026-33913
OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files
Published 2026-03-25 · Analyzed
7.7EPSS 0.005
CVE-2026-34056
OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data
Published 2026-03-25 · Analyzed
7.7EPSS 0.004
CVE-2026-32123
OpenEMR: Therapy Group Sensitivity ACL No Longer Enforced
Published 2026-03-11 · Analyzed
7.7EPSS 0.003
CVE-2025-43860
OpemEMR Vulnerable to Stored XSS Attack in the Additional Address Section of Patient Demographics
Published 2025-05-23 · Analyzed
7.6EPSS 0.141
CVE-2025-32794
OpenEMR Stored XSS via Patient Name Field in Procedure Orders
Published 2025-05-23 · Analyzed
7.6EPSS 0.098
CVE-2026-33321
OpenEMR has Out-of-Band Server-Side Request Forgery (OOB SSRF)
Published 2026-03-19 · Analyzed
7.6EPSS 0.003
CVE-2026-33932
OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes
Published 2026-03-25 · Analyzed
7.6EPSS 0.003
CVE-2012-2115
SQL injection vulnerability in interface/login/validateUser.php in OpenEMR 4.1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the u parameter.
Published 2012-09-09 · Modified
7.51 PoCEPSS 0.021
CVE-2023-22974
A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.
Published 2023-02-22 · Modified
7.5EPSS 0.019
CVE-2017-16540
OpenEMR before 5.0.0 Patch 5 allows unauthenticated remote database copying because setup.php exposes functionality for cloning an existing OpenEMR site to an arbitrary attacker-controlled MySQL server via vectors involving a crafted state parameter.
Published 2017-11-04 · Modified
7.5EPSS 0.013
CVE-2017-12064
The csv_log_html function in library/edihistory/edih_csv_inc.php in OpenEMR 5.0.0 and prior allows attackers to bypass intended access restrictions via a crafted name.
Published 2017-08-01 · Modified
7.5EPSS 0.012
CVE-2022-4504
Improper Input Validation in openemr/openemr
Published 2022-12-15 · Modified
7.5EPSS 0.009
CVE-2025-29789
OpenEMR Has Directory Traversal in Load Code feature
Published 2025-03-25 · Analyzed
7.5EPSS 0.009
CVE-2023-2566
Cross-site Scripting (XSS) - Stored in openemr/openemr
Published 2023-05-08 · Modified
7.5EPSS 0.005
CVE-2025-31117
OpenEMR Out-of-Band Server-Side Request Forgery (OOB SSRF) Vulnerability
Published 2025-03-31 · Analyzed
7.5EPSS 0.005
CVE-2026-25476
OpenEMR has Session Timeout Bypass via skip_timeout_reset
Published 2026-02-25 · Analyzed
7.5EPSS 0.004
← Prev3 / 6Next →