Michael A. Smith
50 exploits
Active since Jan 2026
OpenEMR has Authorization Bypass in Dated Reminders Log
CVSS 6.5
OpenEMR has Authorization Bypass in FaxSMS AppDispatch Constructor
CVSS 5.4
OpenEMR has Out-of-Band Server-Side Request Forgery (OOB SSRF)
CVSS 7.6
OpenEMR has stored XSS in portal_payment.php via Unescaped table_args
CVSS 8.7
OpenEMR's Message Update Ignores Patient id
CVSS 6.5
OpenEMR <8.0.0 - Info Disclosure
CVSS 10.0
OpenEMR <8.0.0 - Auth Bypass
CVSS 7.1
OpenEMR <8.0.0 - Auth Bypass
CVSS 8.1
OpenEMR <8.0.0 - SQL Injection
CVSS 9.9
OpenEMR <8.0.0 - Auth Bypass
CVSS 8.1
OpenEMR <8.0.0 - Privilege Escalation
CVSS 6.5
OpenEMR <8.0.0 - Auth Bypass
CVSS 7.5
OpenEMR <8.0.0 - Stored XSS
CVSS 4.8
OpenEMR <8.0.0 - SQL Injection
CVSS 8.8
OpenEMR <8.0.0 - Auth Bypass
CVSS 6.5
OpenEMR <8.0.0 - Auth Bypass
CVSS 6.5
OpenEMR <7.0.4 - MITM
CVSS 8.1
OpenEMR <8.0.0 - Stored XSS
CVSS 8.7
OpenEMR <8.0.0 - XSS
CVSS 6.1
OpenEMR <7.0.4 - Path Traversal
CVSS 9.9
OpenEMR <8.0.0 - Broken Access Control
CVSS 6.5
OpenEMR <8.0.0 - Privilege Escalation
CVSS 6.5
OpenEMR <8.0.0 - Privilege Escalation
CVSS 6.5
OpenEMR <8.0.0 - Privilege Escalation
CVSS 8.8
Open-emr Openemr - Improper Access Control
CVSS 8.8