Vendorsopen-emropenemrany version
Vulnerabilities

open-emr Openemr any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

182CVEs
CVE-2022-1177
Accounting User Can Download Patient Reports in openemr in openemr/openemr
Published 2022-03-30 · Modified
6.5EPSS 0.009
CVE-2022-2730
Authorization Bypass Through User-Controlled Key in openemr/openemr
Published 2022-08-09 · Modified
6.5EPSS 0.008
CVE-2026-25928
OpenEMR Vulnerable to Path Traversal When Zipping DICOM Folders
Published 2026-03-19 · Analyzed
6.5EPSS 0.007
CVE-2026-33931
OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access
Published 2026-03-25 · Analyzed
6.5EPSS 0.005
CVE-2026-25929
OpenEMR Patient Picture Context Allows Arbitrary Patient Photo Retrieval
Published 2026-02-25 · Analyzed
6.5EPSS 0.005
CVE-2026-25930
OpenEMR's Printable LBF Endpoint Leaks Arbitrary Patient Forms
Published 2026-02-25 · Analyzed
6.5EPSS 0.005
CVE-2026-33304
OpenEMR has Authorization Bypass in Dated Reminders Log
Published 2026-03-19 · Analyzed
6.5EPSS 0.004
CVE-2026-27943
OpenEMR's Eye Exam View Trusts form_id Without Verifying Patient/Encounter Ownership
Published 2026-02-26 · Analyzed
6.5EPSS 0.004
CVE-2026-24488
OpenEMR Vulnerable to Arbitrary File Exfiltration via Fax Endpoint
Published 2026-02-27 · Analyzed
6.5EPSS 0.004
CVE-2026-25744
OpenEMR: POST /api/.../vital Accepts Attacker-Supplied id and Overwrites Arbitrary Vitals
Published 2026-03-19 · Analyzed
6.5EPSS 0.004
CVE-2026-25745
OpenEMR's Message Update Ignores Patient id
Published 2026-03-18 · Modified
6.5EPSS 0.004
CVE-2026-32120
OpenEMR has IDOR in Fee Sheet Product Save
Published 2026-03-25 · Analyzed
6.5EPSS 0.004
CVE-2026-24487
OpenEMR has FHIR Patient Compartment Bypass in CareTeam Resource
Published 2026-02-25 · Analyzed
6.5EPSS 0.003
CVE-2026-25124
OpenEMR has Broken Access Control in Report/Clients/Message List CSV Export
Published 2026-02-25 · Analyzed
6.5EPSS 0.003
CVE-2026-25220
OpenEMR Messages "Show All" Not Restricted to Admins
Published 2026-02-25 · Analyzed
6.5EPSS 0.003
CVE-2026-24896
OpenEMR has Broken Access Control that allows unauthorized access to EDI Logs
Published 2026-02-25 · Analyzed
6.5EPSS 0.003
CVE-2022-4503
Cross-site Scripting (XSS) - Generic in openemr/openemr
Published 2022-12-15 · Modified
6.4EPSS 0.006
CVE-2025-30149
OpenEMR Reflected XSS in AJAX Script
Published 2025-03-31 · Analyzed
6.4EPSS 0.003
CVE-2022-2494
Cross-site Scripting (XSS) - Stored in openemr/openemr
Published 2022-07-22 · Modified
6.3EPSS 0.006
CVE-2023-2944
Improper Access Control in openemr/openemr
Published 2023-05-27 · Modified
6.3EPSS 0.004
CVE-2019-3964
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
Published 2019-08-20 · Modified
6.1EPSS 0.527
CVE-2019-3963
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
Published 2019-08-20 · Modified
6.1EPSS 0.527
CVE-2018-10571
Multiple reflected cross-site scripting (XSS) vulnerabilities in OpenEMR before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) patient parameter to interface/main/finder/finder_navigation.php; (2) key parameter to interface/billing/get_claim_file.php; (3) formid or (4) formseq parameter to interface/orders/types.php; (5) eraname, (6) paydate, (7) post_to_date, (8) deposit_date, (9) debug, or (10) InsId parameter to interface/billing/sl_eob_process.php; (11) form_source, (12) form_paydate, (13) form_deposit_date, (14) form_amount, (15) form_name, (16) form_pid, (17) form_encounter, (18) form_date, or (19) form_to_date parameter to interface/billing/sl_eob_search.php; (20) codetype or (21) search_term parameter to interface/de_identification_forms/find_code_popup.php; (22) search_term parameter to interface/de_identification_forms/find_drug_popup.php; (23) search_term parameter to interface/de_identification_forms/find_immunization_popup.php; (24) id parameter to interface/forms/CAMOS/view.php; (25) id parameter to interface/forms/reviewofs/view.php; or (26) list_id parameter to library/custom_template/personalize.php.
Published 2018-04-30 · Modified
6.1EPSS 0.015
CVE-2019-16862
Reflected XSS in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 allows a remote attacker to execute arbitrary code in the context of a user's session via the pid parameter.
Published 2019-10-21 · Modified
6.1EPSS 0.015
CVE-2019-3965
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the document_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
Published 2019-08-20 · Modified
6.1EPSS 0.013
CVE-2019-3966
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the foreign_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
Published 2019-08-20 · Modified
6.1EPSS 0.013
CVE-2018-18035
A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
Published 2019-04-02 · Modified
6.1EPSS 0.012
CVE-2026-33933
Reflected XSS via Unescaped contextName Parameter in Custom Template Editor
Published 2026-03-25 · Analyzed
6.1EPSS 0.009
CVE-2019-17179
4.1.0, 4.1.1, 4.1.2, 4.1.2.3, 4.1.2.6, 4.1.2.7, 4.2.0, 4.2.1, 4.2.2, 5.0.0, 5.0.0.5, 5.0.0.6, 5.0.1, 5.0.1.1, 5.0.1.2, 5.0.1.3, 5.0.1.4, 5.0.1.5, 5.0.1.6, 5.0.1.7, 5.0.2, fixed in version 5.0.2.1
Published 2019-10-04 · Modified
6.1EPSS 0.009
CVE-2021-25922
In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code.
Published 2021-03-22 · Modified
6.1EPSS 0.008
CVE-2019-17409
Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter.
Published 2019-10-21 · Modified
6.1EPSS 0.008
CVE-2022-2731
Cross-site Scripting (XSS) - Reflected in openemr/openemr
Published 2022-08-09 · Modified
6.1EPSS 0.006
CVE-2026-24847
OpenEMR has Open Redirect in Eye Exam Form
Published 2026-02-25 · Analyzed
6.1EPSS 0.002
CVE-2026-21443
OpenEMR allows inconsistent escaping of translation function output
Published 2026-02-25 · Analyzed
6.1EPSS 0.001
CVE-2026-33909
OpenEMR Vulnerable to SQL Injection via Unsanitized Variables in MedEx Recall/Reminder Processing
Published 2026-03-25 · Analyzed
5.9EPSS 0.004
CVE-2021-25921
In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker could lure an admin to enter a malicious payload and by that initiate the exploit.
Published 2021-03-22 · Modified
5.4EPSS 0.911
CVE-2022-1179
Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in openemr/openemr
Published 2022-03-30 · Modified
5.4EPSS 0.769
CVE-2017-1000240
The application OpenEMR is affected by multiple reflected & stored Cross-Site Scripting (XSS) vulnerabilities affecting version 5.0.0 and prior versions. These vulnerabilities could allow remote authenticated attackers to inject arbitrary web script or HTML.
Published 2017-11-17 · Modified
5.4EPSS 0.007
CVE-2026-33303
OpenEMR Vulnerable to Stored XSS via Unescaped portal_login_username in Credential Print View
Published 2026-03-19 · Analyzed
5.4EPSS 0.007
CVE-2026-32124
OpenEMR: Dynamic Code Picker Renders Unescaped Descriptions (Stored XSS)
Published 2026-03-11 · Analyzed
5.4EPSS 0.006
← Prev4 / 5Next →