OpenEMR Foundation, Inc. Vulnerabilities and Affected Products
Vulnerabilities associated with OpenEMR.
Products
Clear product- OpenEMR1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-47817MEDIUM | OpenEMR 5.0.2.1 - Remote Code ExecutionOpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers can chain with a file upload to achieve remote code execution. Attackers can exploit the vulnerability by crafting a malicious payload to download and execute a web shell, enabling remote command execution on the vulnerable OpenEMR instance. CWE-79Jan 21, 2026 | CVSS4.8v4.0 | EPSS0.667% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |