Vendorsopen-emropenemrall versions
Vulnerabilities

open-emr Openemr

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

221CVEs
CVE-2026-33912
OpenEMR has reflected XSS in ajax_download.php via reportID parameter
Published 2026-03-25 · Analyzed
5.4EPSS 0.003
CVE-2026-34051
OpenEMR has Improper ACL On Import/Export Popup
Published 2026-03-25 · Analyzed
5.4EPSS 0.003
CVE-2026-33911
OpenEMR vulnerable to reflected XSS in graphs.php via title parameter
Published 2026-03-25 · Analyzed
5.4EPSS 0.003
CVE-2026-33915
OpenEMR Missing ACL Checks on Insurance Company API Routes
Published 2026-03-25 · Analyzed
5.4EPSS 0.003
CVE-2025-32967
OpenEMR doesn't log password administration properly
Published 2025-05-23 · Analyzed
5.4EPSS 0.003
CVE-2018-17180
An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php.
Published 2019-05-17 · Modified
5.3EPSS 0.019
CVE-2015-4453
interface/globals.php in OpenEMR 2.x, 3.x, and 4.x before 4.2.0 patch 2 allows remote attackers to bypass authentication and obtain sensitive information via an ignoreAuth=1 value to certain scripts, as demonstrated by (1) interface/fax/fax_dispatch_newpid.php and (2) interface/billing/sl_eob_search.php.
Published 2015-07-05 · Modified
5.0EPSS 0.029
CVE-2023-2947
Cross-site Scripting (XSS) - Stored in openemr/openemr
Published 2023-05-27 · Modified
4.8EPSS 0.904
CVE-2021-25919
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.
Published 2021-03-22 · Modified
4.8EPSS 0.699
CVE-2021-32103
A Stored XSS vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.1 allows a admin authenticated user to inject arbitrary web script or HTML via the lname parameter.
Published 2021-05-07 · Modified
4.8EPSS 0.007
CVE-2021-25918
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the TOTP Authentication method page. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.
Published 2021-03-22 · Modified
4.8EPSS 0.006
CVE-2021-25917
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the U2F USB Device authentication method page. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.
Published 2021-03-22 · Modified
4.8EPSS 0.006
CVE-2022-1180
Reflected Cross Site Scripting in openemr/openemr
Published 2022-03-30 · Modified
4.6EPSS 0.006
CVE-2026-25135
OpenEMR's location resource for Group.$export operation returns entire patient/user population contact information
Published 2026-02-25 · Analyzed
4.5EPSS 0.002
CVE-2026-32119
OpenEMR has Stored DOM XSS via SearchHighlight text-node reconstruction on Custom Report page
Published 2026-03-19 · Analyzed
4.4EPSS 0.006
CVE-2013-4620
Cross-site scripting (XSS) vulnerability in interface/main/onotes/office_comments_full.php in OpenEMR 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the note parameter.
Published 2013-08-09 · Modified
4.31 PoCEPSS 0.033
CVE-2011-5160
Cross-site scripting (XSS) vulnerability in setup.php in OpenEMR 4 allows remote attackers to inject arbitrary web script or HTML via the site parameter.
Published 2012-09-09 · Modified
4.32 PoCEPSS 0.013
CVE-2022-25041
OpenEMR v6.0.0 was discovered to contain an incorrect access control issue.
Published 2022-03-23 · Modified
4.3EPSS 0.008
CVE-2026-33934
OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff Signatures
Published 2026-03-25 · Analyzed
4.3EPSS 0.004
CVE-2026-32122
OpenEMR: Missing Authorization on Claim File Tracker UI and AJAX Endpoint (V2)
Published 2026-03-11 · Analyzed
4.3EPSS 0.003
CVE-2024-26476
An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component.
Published 2024-02-28 · Analyzed
3.5EPSS 0.004
← Prev6 / 6