Showing 1 vulnerability on this page for OpenEMR

Signals CISA KEV Ransomware Nuclei
OpenEMR Foundation, Inc. vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

OpenEMR 5.0.2.1 - Remote Code Execution

OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers can chain with a file upload to achieve remote code execution. Attackers can exploit the vulnerability by crafting a malicious payload to download and execute a web shell, enabling remote command execution on the vulnerable OpenEMR instance.

CWE-79Jan 21, 2026
CVSS4.8v4.0EPSS0.667%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX