Stephen Nielson
4 exploits
Active since Feb 2026
OpenEMR Vulnerable to Stored XSS via Unescaped portal_login_username in Credential Print View
CVSS 5.4
OpenEMR < 8.0.0 - Unauthenticated Authorization Bypass in FHIR CareTeam Endpoint
CVSS 6.5
OpenEMR < 8.0.0 - Authenticated SQL Injection via Patient REST API _sort Parameter
CVSS 9.9
OpenEMR < 8.0.0 - Unauthorized Information Disclosure via System Export Operation
CVSS 4.5