open-emr

217 tracked vulnerabilities.

CVE-2020-13565 MEDIUM
OpenEMR and phpGACL - Open Redirect via return_page Parameter
Feb 10, 2021
CVSS 6.1
EPSS 0.04
CVE-2020-36243 HIGH
OpenEMR 5.0.2.1 - Authenticated OS Command Injection via Patient Portal Backup Endpoint
Feb 07, 2021
CVSS 8.8
EPSS 0.89
CVE-2020-13564 MEDIUM
phpGACL 3.3.7 - Cross-Site Scripting via Template acl_id Parameter
Feb 01, 2021
CVSS 6.1
EPSS 0.42
CVE-2020-13563 MEDIUM
phpGACL 3.3.7 - Cross-Site Scripting via Template Group ID Parameter
Feb 01, 2021
CVSS 6.1
EPSS 0.42
CVE-2020-13562 MEDIUM
phpGACL 3.3.7 - Cross-Site Scripting via Template Action Parameter
Feb 01, 2021
CVSS 6.1
EPSS 0.71
CVE-2020-13569 HIGH
OpenEMR 5.0.2 and 6.0.0 - Cross-Site Request Forgery in GACL Functionality
Jan 28, 2021
CVSS 8.8
EPSS 0.03
CVE-2020-19364 HIGH
OpenEMR 5.0.1 - Authenticated Unrestricted Upload of File with Dangerous Type via controller.php
Jan 20, 2021
CVSS 8.8
EPSS 0.01
CVE-2019-16404 HIGH
OpenEMR < 5.0.2 - Authenticated SQL Injection via providerID Parameter
Oct 21, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-17409 MEDIUM
OpenEMR 5.0.1-5.0.2.1 - Reflected Cross-Site Scripting via id Parameter
Oct 21, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-16862 MEDIUM
OpenEMR 5.0.0-5.0.2.1 - Reflected Cross-Site Scripting via PID Parameter
Oct 21, 2019
CVSS 6.1
EPSS 0.05
CVE-2019-17197 CRITICAL
OpenEMR < 5.0.2 - SQL Injection in Lifestyle Demographic Filter Criteria
Oct 05, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-17179 MEDIUM
OpenEMR < 5.0.2 - Stored Cross-Site Scripting
Oct 04, 2019
CVSS 6.1
EPSS 0.02
CVE-2019-8368 MEDIUM
OpenEMR 5.0.1-6 - Cross-Site Scripting
Sep 16, 2019
CVSS 6.1
EPSS 0.39
CVE-2019-8371 HIGH
OpenEMR 5.0.1-6 - Remote Code Execution via Unrestricted File Upload
Sep 16, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-3968 HIGH
OpenEMR < 5.0.1 - Authenticated OS Command Injection via Scanned Forms Interface
Aug 20, 2019
CVSS 8.8
EPSS 0.54
CVE-2019-3967 MEDIUM
OpenEMR < 5.0.1 - Authenticated Path Traversal via Patient File Download Interface
Aug 20, 2019
CVSS 6.5
EPSS 0.09
CVE-2019-3966 MEDIUM
OpenEMR < 5.0.1 - Reflected Cross-Site Scripting via Foreign ID Parameter
Aug 20, 2019
CVSS 6.1
EPSS 0.29
CVE-2019-3965 MEDIUM
OpenEMR < 5.0.1 - Reflected Cross-Site Scripting via Document ID Parameter
Aug 20, 2019
CVSS 6.1
EPSS 0.29
CVE-2019-3964 MEDIUM
OpenEMR < 5.0.1 - Reflected Cross-Site Scripting via doc_id Parameter
Aug 20, 2019
CVSS 6.1
EPSS 0.22
CVE-2019-3963 MEDIUM
OpenEMR < 5.0.1 - Reflected Cross-Site Scripting via Patient ID Parameter
Aug 20, 2019
CVSS 6.1
EPSS 0.35
CVE-2019-14530 HIGH NUCLEI
OpenEMR < 5.0.2 - Path Traversal and Arbitrary File Deletion via fileName Parameter
Aug 13, 2019
CVSS 8.8
EPSS 0.53
CVE-2019-14529 CRITICAL
OpenEMR < 5.0.2 - SQL Injection via eye_mag/save.php
Aug 02, 2019
CVSS 9.8
EPSS 0.01
CVE-2018-16795 HIGH
OpenEMR 5.0.1.3 - Cross-Site Request Forgery via library/ajax and interface/super
Dec 31, 2020
CVSS 8.8
EPSS 0.00
CVE-2018-17181 CRITICAL
OpenEMR < 5.0.1.7 - SQL Injection via SaveAudit and portalAudit Functions
May 17, 2019
CVSS 9.8
EPSS 0.00
CVE-2018-17180 MEDIUM
OpenEMR < 5.0.1.7 - Path Traversal via docid Parameter in download_template.php
May 17, 2019
CVSS 5.3
EPSS 0.00