Vendorsopen-emropenemr5.0.2.1
Vulnerabilities

open-emr Openemr 5.0.2.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2020-36243
The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can send a POST request that executes arbitrary OS commands via shell metacharacters.
Published 2021-02-07 · Modified
9.0EPSS 0.641
CVE-2021-32102
A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1.
Published 2021-05-07 · Modified
8.8EPSS 0.012
CVE-2021-32104
A SQL injection vulnerability exists (with user privileges) in interface/forms/eye_mag/save.php in OpenEMR 5.0.2.1.
Published 2021-05-07 · Modified
8.8EPSS 0.012
CVE-2021-32101
The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the attacker can then manipulate and read data of every registered patient.
Published 2021-05-07 · Modified
8.2EPSS 0.012
CVE-2021-47817
OpenEMR 5.0.2.1 - Remote Code Execution
Published 2026-01-21 · Modified
5.4EPSS 0.008