vciy

CVEs we hold for Openemr

Records whose assigning authority named Openemr as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-76614OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restoreopenemr
CVE-2026-67612OpenEMR 8.2.0 Stored XSS via import_template.php Template Managementopenemr
CVE-2026-67611OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configurationopenemr
CVE-2026-67610OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Accessopenemr
CVE-2026-46518OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographicsopenemr
CVE-2026-40509OpenEMR < 8.3.0 CSRF via DICOM Viewer web_path Parameteropenemr
CVE-2026-40508OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handleropenemr
CVE-2026-40507OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portalopenemr
CVE-2026-40506OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.phpopenemr
CVE-2026-39932OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injectionopenemr
CVE-2026-39931OpenEMR Authenticated SQL Injection via backup.php Import Featureopenemr
CVE-2026-34056OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Dataopenemr
CVE-2026-34055OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modificationopenemr
CVE-2026-34053OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handleropenemr
CVE-2026-34051OpenEMR has Improper ACL On Import/Export Popupopenemr
CVE-2026-33934OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff Signaturesopenemr
CVE-2026-33933Reflected XSS via Unescaped contextName Parameter in Custom Template Editoropenemr
CVE-2026-33932OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributesopenemr
CVE-2026-33931OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Accessopenemr
CVE-2026-33918OpenEMR Missing Authorization on Claim File Download Endpointopenemr
CVE-2026-33917OpenEMR has SQL Injection in CAMOS Formopenemr
CVE-2026-33915OpenEMR Missing ACL Checks on Insurance Company API Routesopenemr
CVE-2026-33914OpenEMR has SQL Injection in PostCalendar Category Deleteopenemr
CVE-2026-33913OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Filesopenemr
CVE-2026-33912OpenEMR has reflected XSS in ajax_download.php via reportID parameteropenemr
CVE-2026-33911OpenEMR vulnerable to reflected XSS in graphs.php via title parameteropenemr
CVE-2026-33910OpenEMR has a SQL Injection Vulnerability in patient selectionopenemr
CVE-2026-33909OpenEMR Vulnerable to SQL Injection via Unsanitized Variables in MedEx Recall/Reminder Processingopenemr
CVE-2026-33348OpenEMR has Stored XSS in patient encounter Eye Exam form $CHRONIC2 and $CHRONIC3openemr
CVE-2026-33346OpenEMR has stored XSS in portal_payment.php via Unescaped table_argsopenemr
CVE-2026-33321OpenEMR has Out-of-Band Server-Side Request Forgery (OOB SSRF)openemr
CVE-2026-33305OpenEMR has Authorization Bypass in FaxSMS AppDispatch Constructoropenemr
CVE-2026-33304OpenEMR has Authorization Bypass in Dated Reminders Logopenemr
CVE-2026-33303OpenEMR Vulnerable to Stored XSS via Unescaped portal_login_username in Credential Print Viewopenemr
CVE-2026-33302OpenEMR: zhAclCheck Ignores Explicit ACL Deniesopenemr
CVE-2026-33301OpenEMR has arbitrary image file read via PDF generatoropenemr
CVE-2026-33299OpenEMR has Stored XSS in patient encounter Eye Exam form answersopenemr
CVE-2026-32238OpenEMR has Remote Code Execution in backup functionalityopenemr
CVE-2026-32127SQL Injection Vulnerability in ajax graphs library (OpenEMR)openemr
CVE-2026-32126OpenEMR: Inverted ACL Condition in CDR ControllerRouter Allows Any Authenticated User to Modify/Delete Clinical Rules…openemr
CVE-2026-32125OpenEMR: Stored XSS in Track Anything Graphs via Unescaped Dygraph Titles/Labelsopenemr
CVE-2026-32124OpenEMR: Dynamic Code Picker Renders Unescaped Descriptions (Stored XSS)openemr
CVE-2026-32123OpenEMR: Therapy Group Sensitivity ACL No Longer Enforcedopenemr
CVE-2026-32122OpenEMR: Missing Authorization on Claim File Tracker UI and AJAX Endpoint (V2)openemr
CVE-2026-32121OpenEMR: Stored DOM XSS via `.html()` in Portal Signer Modalopenemr
CVE-2026-32120OpenEMR has IDOR in Fee Sheet Product Saveopenemr
CVE-2026-32119OpenEMR has Stored DOM XSS via SearchHighlight text-node reconstruction on Custom Report pageopenemr
CVE-2026-32118OpenEMR has Stored XSS in Graphical Pain Map legend via unescaped annotation textopenemr
CVE-2026-29187OpenEMR Vulnerable to Authenticated Blind Boolean-Based SQL Injection in new_search_popup.phpopenemr
CVE-2026-27943OpenEMR's Eye Exam View Trusts form_id Without Verifying Patient/Encounter Ownershipopenemr
CVE-2026-25930OpenEMR's Printable LBF Endpoint Leaks Arbitrary Patient Formsopenemr
CVE-2026-25929OpenEMR Patient Picture Context Allows Arbitrary Patient Photo Retrievalopenemr
CVE-2026-25928OpenEMR Vulnerable to Path Traversal When Zipping DICOM Foldersopenemr
CVE-2026-25927OpenEMR Missing Authorization Checks in DICOM Viewer State APIopenemr
CVE-2026-25746OpenEMR has SQL Injection Vulnerabilityopenemr
CVE-2026-25745OpenEMR's Message Update Ignores Patient idopenemr
CVE-2026-25744OpenEMR: POST /api/.../vital Accepts Attacker-Supplied id and Overwrites Arbitrary Vitalsopenemr
CVE-2026-25743OpenEMR has Stored XSS in Questionnaire answersopenemr
CVE-2026-25476OpenEMR has Session Timeout Bypass via skip_timeout_resetopenemr
CVE-2026-25220OpenEMR Messages "Show All" Not Restricted to Adminsopenemr
CVE-2026-25164OpenEMR's Document and Insurance REST Endpoints Skip ACLopenemr
CVE-2026-25147OpenEMR's Portal Payment Endpoint Trusts User-Controlled pidopenemr
CVE-2026-25146OpenEMR's payments gateway_api_key secret rendered into client JS codeopenemr
CVE-2026-25135OpenEMR's location resource for Group.$export operation returns entire patient/user population contact informationopenemr
CVE-2026-25131OpenEMR has Broken Access Control in Procedures Configurationopenemr
CVE-2026-25127OpenEMR has Broken Access Control on Care Coordination Moduleopenemr
CVE-2026-25124OpenEMR has Broken Access Control in Report/Clients/Message List CSV Exportopenemr
CVE-2026-24908OpenEMR has SQL Injection in Patient API Sort Parameteropenemr
CVE-2026-24898OpenEMR has an Unauthenticated MedEx Token Disclosureopenemr
CVE-2026-24896OpenEMR has Broken Access Control that allows unauthorized access to EDI Logsopenemr
CVE-2026-24890OpenEMR Portal Users Can Forge Provider Signaturesopenemr
CVE-2026-24849OpenEMR Arbitrary File Read Vulnerabilityopenemr
CVE-2026-24848OpenEMR Arbitrary File Write leading to Remote Code Executionopenemr
CVE-2026-24847OpenEMR has Open Redirect in Eye Exam Formopenemr
CVE-2026-24488OpenEMR Vulnerable to Arbitrary File Exfiltration via Fax Endpointopenemr
CVE-2026-24487OpenEMR has FHIR Patient Compartment Bypass in CareTeam Resourceopenemr
CVE-2026-23627OpenEMR has SQL Injection in Immunization Search/Reportopenemr
CVE-2026-21443OpenEMR allows inconsistent escaping of translation function outputopenemr
CVE-2025-69231OpenEMR has a Stored XSS in GAD-7 Form that Enables Session Hijacking and Privilege Escalationopenemr
CVE-2025-68277OpenEMR allows links sent via Secure Messaging to be opened in OpenEMR and Portalopenemr
CVE-2025-67752OpenEMR Has Disabled SSL Certificate Verification in HTTP Clientopenemr
CVE-2025-67645OpenEMR Vulnerable to Broken Access Control in Profile Edit Endpointopenemr
CVE-2025-67491OpenEMR has Stored XSS in ub04 helperopenemr
CVE-2025-54373OpenEMR may expose Contents of Clinical Notes and Care Planto users who do not have Sensitivities=high privilegeopenemr
CVE-2025-43860OpemEMR Vulnerable to Stored XSS Attack in the Additional Address Section of Patient Demographicsopenemr
CVE-2025-32967OpenEMR doesn't log password administration properlyopenemr
CVE-2025-32794OpenEMR Stored XSS via Patient Name Field in Procedure Ordersopenemr
CVE-2025-31121OpenEMR allows XSS in Patient Image featureopenemr
CVE-2025-31117OpenEMR Out-of-Band Server-Side Request Forgery (OOB SSRF) Vulnerabilityopenemr
CVE-2025-30161OpenEMR Stored XSS in OpenEMR Bronchitis Formopenemr
CVE-2025-30149OpenEMR Reflected XSS in AJAX Scriptopenemr
CVE-2025-29789OpenEMR Has Directory Traversal in Load Code featureopenemr
CVE-2025-29772OpenEMR allows Reflected XSS in CAMOS new.phpopenemr
CVE-2024-0875Stored XSS in openemr/openemropenemr/openemr
CVE-2023-2950Improper Authorization in openemr/openemropenemr/openemr
CVE-2023-2949Cross-site Scripting (XSS) - Reflected in openemr/openemropenemr/openemr
CVE-2023-2948Cross-site Scripting (XSS) - Generic in openemr/openemropenemr/openemr
CVE-2023-2947Cross-site Scripting (XSS) - Stored in openemr/openemropenemr/openemr
CVE-2023-2946Improper Access Control in openemr/openemropenemr/openemr
CVE-2023-2945Missing Authorization in openemr/openemropenemr/openemr
CVE-2023-2944Improper Access Control in openemr/openemropenemr/openemr
CVE-2023-2943Code Injection in openemr/openemropenemr/openemr
CVE-2023-2942Improper Input Validation in openemr/openemropenemr/openemr
CVE-2023-2674Improper Access Control in openemr/openemropenemr/openemr
CVE-2023-2566Cross-site Scripting (XSS) - Stored in openemr/openemropenemr/openemr
CVE-2022-4733Cross-site Scripting (XSS) - Stored in openemr/openemropenemr/openemr
CVE-2022-4615Cross-site Scripting (XSS) - Reflected in openemr/openemropenemr/openemr
CVE-2022-4567Improper Access Control in openemr/openemropenemr/openemr
CVE-2022-4506Unrestricted Upload of File with Dangerous Type in openemr/openemropenemr/openemr
CVE-2022-4505Authorization Bypass Through User-Controlled Key in openemr/openemropenemr/openemr
CVE-2022-4504Improper Input Validation in openemr/openemropenemr/openemr
CVE-2022-4503Cross-site Scripting (XSS) - Generic in openemr/openemropenemr/openemr
CVE-2022-4502Cross-site Scripting (XSS) - Reflected in openemr/openemropenemr/openemr
CVE-2022-2824Authorization Bypass Through User-Controlled Key in openemr/openemropenemr/openemr
CVE-2022-2734Improper Restriction of Rendered UI Layers or Frames in openemr/openemropenemr/openemr
CVE-2022-2733Cross-site Scripting (XSS) - Reflected in openemr/openemropenemr/openemr
CVE-2022-2732Missing Authorization in openemr/openemropenemr/openemr
CVE-2022-2731Cross-site Scripting (XSS) - Reflected in openemr/openemropenemr/openemr
CVE-2022-2730Authorization Bypass Through User-Controlled Key in openemr/openemropenemr/openemr
CVE-2022-2729Cross-site Scripting (XSS) - DOM in openemr/openemropenemr/openemr
CVE-2022-2494Cross-site Scripting (XSS) - Stored in openemr/openemropenemr/openemr
CVE-2022-2493Data Access from Outside Expected Data Manager Component in openemr/openemropenemr/openemr
CVE-2022-1461Non Privilege User can Enable or Disable Registered in openemr/openemropenemr/openemr
CVE-2022-1459Non-Privilege User Can View Patient’s Disclosures in openemr/openemropenemr/openemr
CVE-2022-1458Stored XSS Leads To Session Hijacking in openemr/openemropenemr/openemr
CVE-2022-1181Stored Cross Site Scripting in openemr/openemropenemr/openemr
CVE-2022-1180Reflected Cross Site Scripting in openemr/openemropenemr/openemr
CVE-2022-1179Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in openemr/openemropenemr/openemr
CVE-2022-1178Stored Cross Site Scripting in openemr/openemropenemr/openemr
CVE-2022-1177Accounting User Can Download Patient Reports in openemr in openemr/openemropenemr/openemr
CVE-2021-47817OpenEMR 5.0.2.1 - Remote Code ExecutionOpenEMR
CVE-2021-25923no title heldn/a openemr
CVE-2021-25922no title heldn/a openemr
CVE-2021-25921no title heldn/a openemr
CVE-2021-25920no title heldn/a openemr
CVE-2021-25919no title heldn/a openemr
CVE-2021-25918no title heldn/a openemr
CVE-2021-25917no title heldn/a openemr
CVE-2020-13569no title heldn/a OpenEMR
CVE-2020-13567no title heldOpenEMR; phpGACL
CVE-2019-3968no title heldn/a OpenEMR
CVE-2019-3967no title heldn/a OpenEMR
CVE-2019-3966no title heldn/a OpenEMR
CVE-2019-3965no title heldn/a OpenEMR
CVE-2019-3964no title heldn/a OpenEMR
CVE-2019-3963no title heldn/a OpenEMR
CVE-2013-10044OpenEMR ≤ 4.1.1 SQL Injection Privilege Escalation and RCEOpenEMR

147 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.