Home / CVEs we hold for Openemr CVEs we hold for Openemr Records whose assigning authority named Openemr as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-76614 OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore openemr CVE-2026-67612 OpenEMR 8.2.0 Stored XSS via import_template.php Template Management openemr CVE-2026-67611 OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration openemr CVE-2026-67610 OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access openemr CVE-2026-46518 OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics openemr CVE-2026-40509 OpenEMR < 8.3.0 CSRF via DICOM Viewer web_path Parameter openemr CVE-2026-40508 OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler openemr CVE-2026-40507 OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portal openemr CVE-2026-40506 OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.php openemr CVE-2026-39932 OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection openemr CVE-2026-39931 OpenEMR Authenticated SQL Injection via backup.php Import Feature openemr CVE-2026-34056 OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data openemr CVE-2026-34055 OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification openemr CVE-2026-34053 OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler openemr CVE-2026-33934 OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff Signatures openemr CVE-2026-33933 Reflected XSS via Unescaped contextName Parameter in Custom Template Editor openemr CVE-2026-33932 OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes openemr CVE-2026-33931 OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access openemr CVE-2026-33918 OpenEMR Missing Authorization on Claim File Download Endpoint openemr CVE-2026-33915 OpenEMR Missing ACL Checks on Insurance Company API Routes openemr CVE-2026-33914 OpenEMR has SQL Injection in PostCalendar Category Delete openemr CVE-2026-33913 OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files openemr CVE-2026-33912 OpenEMR has reflected XSS in ajax_download.php via reportID parameter openemr CVE-2026-33911 OpenEMR vulnerable to reflected XSS in graphs.php via title parameter openemr CVE-2026-33910 OpenEMR has a SQL Injection Vulnerability in patient selection openemr CVE-2026-33909 OpenEMR Vulnerable to SQL Injection via Unsanitized Variables in MedEx Recall/Reminder Processing openemr CVE-2026-33348 OpenEMR has Stored XSS in patient encounter Eye Exam form $CHRONIC2 and $CHRONIC3 openemr CVE-2026-33346 OpenEMR has stored XSS in portal_payment.php via Unescaped table_args openemr CVE-2026-33321 OpenEMR has Out-of-Band Server-Side Request Forgery (OOB SSRF) openemr CVE-2026-33305 OpenEMR has Authorization Bypass in FaxSMS AppDispatch Constructor openemr CVE-2026-33304 OpenEMR has Authorization Bypass in Dated Reminders Log openemr CVE-2026-33303 OpenEMR Vulnerable to Stored XSS via Unescaped portal_login_username in Credential Print View openemr CVE-2026-33301 OpenEMR has arbitrary image file read via PDF generator openemr CVE-2026-33299 OpenEMR has Stored XSS in patient encounter Eye Exam form answers openemr CVE-2026-32238 OpenEMR has Remote Code Execution in backup functionality openemr CVE-2026-32127 SQL Injection Vulnerability in ajax graphs library (OpenEMR) openemr CVE-2026-32126 OpenEMR: Inverted ACL Condition in CDR ControllerRouter Allows Any Authenticated User to Modify/Delete Clinical Rules… openemr CVE-2026-32125 OpenEMR: Stored XSS in Track Anything Graphs via Unescaped Dygraph Titles/Labels openemr CVE-2026-32124 OpenEMR: Dynamic Code Picker Renders Unescaped Descriptions (Stored XSS) openemr CVE-2026-32123 OpenEMR: Therapy Group Sensitivity ACL No Longer Enforced openemr CVE-2026-32122 OpenEMR: Missing Authorization on Claim File Tracker UI and AJAX Endpoint (V2) openemr CVE-2026-32121 OpenEMR: Stored DOM XSS via `.html()` in Portal Signer Modal openemr CVE-2026-32119 OpenEMR has Stored DOM XSS via SearchHighlight text-node reconstruction on Custom Report page openemr CVE-2026-32118 OpenEMR has Stored XSS in Graphical Pain Map legend via unescaped annotation text openemr CVE-2026-29187 OpenEMR Vulnerable to Authenticated Blind Boolean-Based SQL Injection in new_search_popup.php openemr CVE-2026-27943 OpenEMR's Eye Exam View Trusts form_id Without Verifying Patient/Encounter Ownership openemr CVE-2026-25930 OpenEMR's Printable LBF Endpoint Leaks Arbitrary Patient Forms openemr CVE-2026-25929 OpenEMR Patient Picture Context Allows Arbitrary Patient Photo Retrieval openemr CVE-2026-25928 OpenEMR Vulnerable to Path Traversal When Zipping DICOM Folders openemr CVE-2026-25927 OpenEMR Missing Authorization Checks in DICOM Viewer State API openemr CVE-2026-25744 OpenEMR: POST /api/.../vital Accepts Attacker-Supplied id and Overwrites Arbitrary Vitals openemr CVE-2026-25476 OpenEMR has Session Timeout Bypass via skip_timeout_reset openemr CVE-2026-25220 OpenEMR Messages "Show All" Not Restricted to Admins openemr CVE-2026-25164 OpenEMR's Document and Insurance REST Endpoints Skip ACL openemr CVE-2026-25147 OpenEMR's Portal Payment Endpoint Trusts User-Controlled pid openemr CVE-2026-25146 OpenEMR's payments gateway_api_key secret rendered into client JS code openemr CVE-2026-25135 OpenEMR's location resource for Group.$export operation returns entire patient/user population contact information openemr CVE-2026-25131 OpenEMR has Broken Access Control in Procedures Configuration openemr CVE-2026-25127 OpenEMR has Broken Access Control on Care Coordination Module openemr CVE-2026-25124 OpenEMR has Broken Access Control in Report/Clients/Message List CSV Export openemr CVE-2026-24908 OpenEMR has SQL Injection in Patient API Sort Parameter openemr CVE-2026-24898 OpenEMR has an Unauthenticated MedEx Token Disclosure openemr CVE-2026-24896 OpenEMR has Broken Access Control that allows unauthorized access to EDI Logs openemr CVE-2026-24890 OpenEMR Portal Users Can Forge Provider Signatures openemr CVE-2026-24848 OpenEMR Arbitrary File Write leading to Remote Code Execution openemr CVE-2026-24488 OpenEMR Vulnerable to Arbitrary File Exfiltration via Fax Endpoint openemr CVE-2026-24487 OpenEMR has FHIR Patient Compartment Bypass in CareTeam Resource openemr CVE-2026-23627 OpenEMR has SQL Injection in Immunization Search/Report openemr CVE-2026-21443 OpenEMR allows inconsistent escaping of translation function output openemr CVE-2025-69231 OpenEMR has a Stored XSS in GAD-7 Form that Enables Session Hijacking and Privilege Escalation openemr CVE-2025-68277 OpenEMR allows links sent via Secure Messaging to be opened in OpenEMR and Portal openemr CVE-2025-67752 OpenEMR Has Disabled SSL Certificate Verification in HTTP Client openemr CVE-2025-67645 OpenEMR Vulnerable to Broken Access Control in Profile Edit Endpoint openemr CVE-2025-54373 OpenEMR may expose Contents of Clinical Notes and Care Planto users who do not have Sensitivities=high privilege openemr CVE-2025-43860 OpemEMR Vulnerable to Stored XSS Attack in the Additional Address Section of Patient Demographics openemr CVE-2025-32967 OpenEMR doesn't log password administration properly openemr CVE-2025-32794 OpenEMR Stored XSS via Patient Name Field in Procedure Orders openemr CVE-2025-31117 OpenEMR Out-of-Band Server-Side Request Forgery (OOB SSRF) Vulnerability openemr CVE-2025-29789 OpenEMR Has Directory Traversal in Load Code feature openemr CVE-2023-2950 Improper Authorization in openemr/openemr openemr/openemr CVE-2023-2949 Cross-site Scripting (XSS) - Reflected in openemr/openemr openemr/openemr CVE-2023-2948 Cross-site Scripting (XSS) - Generic in openemr/openemr openemr/openemr CVE-2023-2947 Cross-site Scripting (XSS) - Stored in openemr/openemr openemr/openemr CVE-2023-2946 Improper Access Control in openemr/openemr openemr/openemr CVE-2023-2945 Missing Authorization in openemr/openemr openemr/openemr CVE-2023-2944 Improper Access Control in openemr/openemr openemr/openemr CVE-2023-2942 Improper Input Validation in openemr/openemr openemr/openemr CVE-2023-2674 Improper Access Control in openemr/openemr openemr/openemr CVE-2023-2566 Cross-site Scripting (XSS) - Stored in openemr/openemr openemr/openemr CVE-2022-4733 Cross-site Scripting (XSS) - Stored in openemr/openemr openemr/openemr CVE-2022-4615 Cross-site Scripting (XSS) - Reflected in openemr/openemr openemr/openemr CVE-2022-4567 Improper Access Control in openemr/openemr openemr/openemr CVE-2022-4506 Unrestricted Upload of File with Dangerous Type in openemr/openemr openemr/openemr CVE-2022-4505 Authorization Bypass Through User-Controlled Key in openemr/openemr openemr/openemr CVE-2022-4504 Improper Input Validation in openemr/openemr openemr/openemr CVE-2022-4503 Cross-site Scripting (XSS) - Generic in openemr/openemr openemr/openemr CVE-2022-4502 Cross-site Scripting (XSS) - Reflected in openemr/openemr openemr/openemr CVE-2022-2824 Authorization Bypass Through User-Controlled Key in openemr/openemr openemr/openemr CVE-2022-2734 Improper Restriction of Rendered UI Layers or Frames in openemr/openemr openemr/openemr CVE-2022-2733 Cross-site Scripting (XSS) - Reflected in openemr/openemr openemr/openemr CVE-2022-2732 Missing Authorization in openemr/openemr openemr/openemr CVE-2022-2731 Cross-site Scripting (XSS) - Reflected in openemr/openemr openemr/openemr CVE-2022-2730 Authorization Bypass Through User-Controlled Key in openemr/openemr openemr/openemr CVE-2022-2729 Cross-site Scripting (XSS) - DOM in openemr/openemr openemr/openemr CVE-2022-2494 Cross-site Scripting (XSS) - Stored in openemr/openemr openemr/openemr CVE-2022-2493 Data Access from Outside Expected Data Manager Component in openemr/openemr openemr/openemr CVE-2022-1461 Non Privilege User can Enable or Disable Registered in openemr/openemr openemr/openemr CVE-2022-1459 Non-Privilege User Can View Patient’s Disclosures in openemr/openemr openemr/openemr CVE-2022-1458 Stored XSS Leads To Session Hijacking in openemr/openemr openemr/openemr CVE-2022-1181 Stored Cross Site Scripting in openemr/openemr openemr/openemr CVE-2022-1180 Reflected Cross Site Scripting in openemr/openemr openemr/openemr CVE-2022-1179 Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in openemr/openemr openemr/openemr CVE-2022-1178 Stored Cross Site Scripting in openemr/openemr openemr/openemr CVE-2022-1177 Accounting User Can Download Patient Reports in openemr in openemr/openemr openemr/openemr CVE-2013-10044 OpenEMR ≤ 4.1.1 SQL Injection Privilege Escalation and RCE OpenEMR 147 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.