CVE-2026-33910

HIGH

OpenEMR has a SQL Injection Vulnerability in patient selection

Title source: cna

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Versions up to and including 8.0.0.2 contain a SQL injection vulnerability in the patient selection feature that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the patient selection feature. Version 8.0.0.3 contains a patch.

Exploits (1)

nomisec WORKING POC
by ChrisSub08 · poc
https://github.com/ChrisSub08/CVE-2026-33910_SqlInjectionVulnerabilityOpenEMR8.0.0.2

Scores

CVSS v3 7.2
EPSS 0.0000
EPSS Percentile 0.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
open-emr/openemr < 8.0.0.3
openemr/openemr < 8.0.0.3
Published Mar 25, 2026
Tracked Since Mar 26, 2026