open-emr

217 tracked vulnerabilities.

CVE-2026-34056 HIGH
OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data
Mar 26, 2026
CVSS 7.7
EPSS 0.00
CVE-2026-34055 HIGH
OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification
Mar 26, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-34053 HIGH
OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler
Mar 26, 2026
CVSS 7.1
EPSS 0.00
CVE-2026-34051 MEDIUM
OpenEMR has Improper ACL On Import/Export Popup
Mar 26, 2026
CVSS 5.4
EPSS 0.00
CVE-2026-33934 MEDIUM
OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff Signatures
Mar 26, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-33933 MEDIUM
Reflected XSS via Unescaped contextName Parameter in Custom Template Editor
Mar 26, 2026
CVSS 6.1
EPSS 0.00
CVE-2026-33932 HIGH
OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes
Mar 26, 2026
CVSS 7.6
EPSS 0.00
CVE-2026-33931 MEDIUM
OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access
Mar 26, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-33918 HIGH
OpenEMR Missing Authorization on Claim File Download Endpoint
Mar 26, 2026
CVSS 7.6
EPSS 0.00
CVE-2026-33917 HIGH
OpenEMR has SQL Injection in CAMOS Form
Mar 26, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-33915 MEDIUM
OpenEMR Missing ACL Checks on Insurance Company API Routes
Mar 26, 2026
CVSS 5.4
EPSS 0.00
CVE-2026-33914 HIGH
OpenEMR has SQL Injection in PostCalendar Category Delete
Mar 26, 2026
CVSS 7.2
EPSS 0.00
CVE-2026-33913 HIGH
OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files
Mar 25, 2026
CVSS 7.7
EPSS 0.00
CVE-2026-33912 MEDIUM
OpenEMR has reflected XSS in ajax_download.php via reportID parameter
Mar 25, 2026
CVSS 5.4
EPSS 0.00
CVE-2026-33911 MEDIUM
OpenEMR vulnerable to reflected XSS in graphs.php via title parameter
Mar 25, 2026
CVSS 5.4
EPSS 0.00
CVE-2026-33910 HIGH
OpenEMR has a SQL Injection Vulnerability in patient selection
Mar 25, 2026
CVSS 7.2
EPSS 0.00
CVE-2026-33909 MEDIUM
OpenEMR Vulnerable to SQL Injection via Unsanitized Variables in MedEx Recall/Reminder Processing
Mar 25, 2026
CVSS 5.9
EPSS 0.00
CVE-2026-33348 HIGH
OpenEMR has Stored XSS in patient encounter Eye Exam form $CHRONIC2 and $CHRONIC3
Mar 25, 2026
CVSS 8.7
EPSS 0.00
CVE-2026-32120 MEDIUM
OpenEMR has IDOR in Fee Sheet Product Save
Mar 25, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-29187 HIGH
OpenEMR Vulnerable to Authenticated Blind Boolean-Based SQL Injection in new_search_popup.php
Mar 25, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-33346 HIGH
OpenEMR has stored XSS in portal_payment.php via Unescaped table_args
Mar 19, 2026
CVSS 8.7
EPSS 0.00
CVE-2026-33321 HIGH
OpenEMR has Out-of-Band Server-Side Request Forgery (OOB SSRF)
Mar 19, 2026
CVSS 7.6
EPSS 0.00
CVE-2026-33305 MEDIUM
OpenEMR has Authorization Bypass in FaxSMS AppDispatch Constructor
Mar 19, 2026
CVSS 5.4
EPSS 0.00
CVE-2026-33304 MEDIUM
OpenEMR has Authorization Bypass in Dated Reminders Log
Mar 19, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-33303 MEDIUM
OpenEMR Vulnerable to Stored XSS via Unescaped portal_login_username in Credential Print View
Mar 19, 2026
CVSS 5.4
EPSS 0.00