Michael A. Smith
50 exploits
Active since Jan 2026
OpenEMR Vulnerable to Authenticated Blind Boolean-Based SQL Injection in new_search_popup.php
CVSS 8.1
OpenEMR has IDOR in Fee Sheet Product Save
CVSS 6.5
OpenEMR has Stored XSS in patient encounter Eye Exam form $CHRONIC2 and $CHRONIC3
CVSS 8.7
OpenEMR Vulnerable to SQL Injection via Unsanitized Variables in MedEx Recall/Reminder Processing
CVSS 5.9
OpenEMR vulnerable to reflected XSS in graphs.php via title parameter
CVSS 5.4
OpenEMR has reflected XSS in ajax_download.php via reportID parameter
CVSS 5.4
OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files
CVSS 7.7
OpenEMR has SQL Injection in PostCalendar Category Delete
CVSS 7.2
OpenEMR Missing ACL Checks on Insurance Company API Routes
CVSS 5.4
OpenEMR has SQL Injection in CAMOS Form
CVSS 8.8
OpenEMR Missing Authorization on Claim File Download Endpoint
CVSS 7.6
OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access
CVSS 6.5
OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes
CVSS 7.6
OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff Signatures
CVSS 4.3
OpenEMR has Improper ACL On Import/Export Popup
CVSS 5.4
OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler
CVSS 7.1
OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification
CVSS 8.1
OpenEMR: POST /api/.../vital Accepts Attacker-Supplied id and Overwrites Arbitrary Vitals
CVSS 6.5
OpenEMR Vulnerable to Path Traversal When Zipping DICOM Folders
CVSS 6.5
OpenEMR has Stored DOM XSS via SearchHighlight text-node reconstruction on Custom Report page
CVSS 4.4
OpenEMR has Remote Code Execution in backup functionality
CVSS 9.1
OpenEMR has Stored XSS in patient encounter Eye Exam form answers
CVSS 5.4
OpenEMR has arbitrary image file read via PDF generator
CVSS 8.1
OpenEMR: zhAclCheck Ignores Explicit ACL Denies
CVSS 8.1
OpenEMR Vulnerable to Stored XSS via Unescaped portal_login_username in Credential Print View
CVSS 5.4