open-emr

217 tracked vulnerabilities.

CVE-2023-22972 MEDIUM
OpenEMR < 7.0.0 - Authenticated Reflected Cross-Site Scripting via REQUEST_URI
Feb 22, 2023
CVSS 5.4
EPSS 0.00
CVE-2022-4733 MEDIUM
OpenEMR < 7.0.0.2 - Stored Cross-Site Scripting
Dec 27, 2022
CVSS 4.8
EPSS 0.01
CVE-2022-4615 MEDIUM
OpenEMR < 7.0.0.2 - Reflected Cross-Site Scripting
Dec 19, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-4567 HIGH
GitHub openemr/openemr <7.0.0.2 - Info Disclosure
Dec 17, 2022
CVSS 8.1
EPSS 0.00
CVE-2022-4506 HIGH
OpenEMR < 7.0.0.2 - Unrestricted Upload of File with Dangerous Type
Dec 15, 2022
CVSS 8.8
EPSS 0.00
CVE-2022-4505 HIGH
OpenEMR < 7.0.0.2 - Authorization Bypass Through User-Controlled Key
Dec 15, 2022
CVSS 8.8
EPSS 0.01
CVE-2022-4504 HIGH
OpenEMR < 7.0.0.2 - Improper Input Validation
Dec 15, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-4503 MEDIUM
OpenEMR < 7.0.0.2 - Cross-Site Scripting
Dec 15, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-4502 MEDIUM
OpenEMR < 7.0.0.2 - Reflected Cross-Site Scripting
Dec 15, 2022
CVSS 6.1
EPSS 0.04
CVE-2022-2824 HIGH
GitHub openemr/openemr <7.0.0.1 - Auth Bypass
Aug 15, 2022
CVSS 8.8
EPSS 0.01
CVE-2022-2734 MEDIUM
openemr/openemr <7.0.0.1 - Info Disclosure
Aug 09, 2022
CVSS 5.4
EPSS 0.01
CVE-2022-2733 MEDIUM NUCLEI
OpenEMR < 7.0.0.1 - Reflected Cross-Site Scripting
Aug 09, 2022
CVSS 6.1
EPSS 0.90
CVE-2022-2732 HIGH
openemr < 7.0.0.1 - Missing Authorization
Aug 09, 2022
CVSS 8.3
EPSS 0.00
CVE-2022-2731 MEDIUM
OpenEMR < 7.0.0.1 - Reflected Cross-Site Scripting
Aug 09, 2022
CVSS 6.1
EPSS 0.02
CVE-2022-2730 MEDIUM
OpenEMR < 7.0.0.1 - Authorization Bypass Through User-Controlled Key
Aug 09, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-2729 MEDIUM
OpenEMR < 7.0.0.1 - DOM-Based Cross-Site Scripting
Aug 09, 2022
CVSS 5.4
EPSS 0.03
CVE-2022-2494 MEDIUM
OpenEMR < 7.0.0 - Stored Cross-Site Scripting
Jul 22, 2022
CVSS 5.4
EPSS 0.18
CVE-2022-2493 HIGH
GitHub openemr/openemr <7.0.0 - Info Disclosure
Jul 22, 2022
CVSS 8.1
EPSS 0.00
CVE-2022-1461 MEDIUM
OpenEMR < 6.1.0.1 - Insufficient Access Control for User Registration Settings
Apr 25, 2022
CVSS 6.5
EPSS 0.02
CVE-2022-1459 HIGH
openemr/openemr <6.1.0.1 - Info Disclosure
Apr 25, 2022
CVSS 8.3
EPSS 0.00
CVE-2022-1458 MEDIUM
OpenEMR < 6.1.0.1 - Stored Cross-Site Scripting
Apr 25, 2022
CVSS 5.4
EPSS 0.10
CVE-2022-1181 MEDIUM
OpenEMR < 6.0.0.2 - Stored Cross-Site Scripting
Mar 30, 2022
CVSS 5.4
EPSS 0.16
CVE-2022-1180 LOW
openemr < 6.0.0.4 - Reflected Cross-Site Scripting
Mar 30, 2022
CVSS 3.5
EPSS 0.19
CVE-2022-1179 MEDIUM
OpenEMR < 6.0.0.4 - Stored Cross-Site Scripting via Rule Creation
Mar 30, 2022
CVSS 5.4
EPSS 0.31
CVE-2022-1178 MEDIUM
OpenEMR < 6.0.0.4 - Stored Cross-Site Scripting
Mar 30, 2022
CVSS 5.4
EPSS 0.14