vciy

openemr: 20 records in one advisory

20 records announced together, published 2026-03-25, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://github.com/openemr/openemr/releases/tag/v8_0_0_3. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

Every record names something of its own, listed against it below.

Most commonly mapped weakness across the batch: CWE-79: Improper Neutralization of Input During…

What this page does not cover

Every record citing this advisory is on this page.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2026-29187OpenEMR Vulnerable to Authenticated Blind Boolean-Based SQL Injection in new_search_popup.phpCWE-89: Improper Neutralization of Special…
CVE-2026-32120OpenEMR has IDOR in Fee Sheet Product SaveCWE-639: Authorization Bypass Through…
CVE-2026-33348OpenEMR has Stored XSS in patient encounter Eye Exam form $CHRONIC2 and $CHRONIC3CWE-79: Improper Neutralization of Input During…
CVE-2026-33909OpenEMR Vulnerable to SQL Injection via Unsanitized Variables in MedEx Recall/Reminder ProcessingCWE-89: Improper Neutralization of Special…
CVE-2026-33910OpenEMR has a SQL Injection Vulnerability in patient selectionCWE-89: Improper Neutralization of Special…
CVE-2026-33911OpenEMR vulnerable to reflected XSS in graphs.php via title parameterCWE-79: Improper Neutralization of Input During…
CVE-2026-33912OpenEMR has reflected XSS in ajax_download.php via reportID parameterCWE-79: Improper Neutralization of Input During…
CVE-2026-33913OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server FilesCWE-611: Improper Restriction of XML External…
CVE-2026-33914OpenEMR has SQL Injection in PostCalendar Category DeleteCWE-89: Improper Neutralization of Special…
CVE-2026-33915OpenEMR Missing ACL Checks on Insurance Company API RoutesCWE-862: Missing Authorization
CVE-2026-33917OpenEMR has SQL Injection in CAMOS FormCWE-89: Improper Neutralization of Special…
CVE-2026-33918OpenEMR Missing Authorization on Claim File Download EndpointCWE-862: Missing Authorization
CVE-2026-33931OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record AccessCWE-639: Authorization Bypass Through…
CVE-2026-33932OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml AttributesCWE-79: Improper Neutralization of Input During…
CVE-2026-33933Reflected XSS via Unescaped contextName Parameter in Custom Template EditorCWE-79: Improper Neutralization of Input During…
CVE-2026-33934OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff SignaturesCWE-639: Authorization Bypass Through…
CVE-2026-34051OpenEMR has Improper ACL On Import/Export PopupCWE-285: Improper Authorization
CVE-2026-34053OpenEMR Missing Authorization in Procedure Order AJAX Deletion HandlerCWE-862: Missing Authorization
CVE-2026-34055OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modificationCWE-639: Authorization Bypass Through…
CVE-2026-34056OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only DataCWE-285: Improper Authorization

20 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.