Vulnerabilities (CVE)

Filtered by vendor Open-emr Subscribe
Total 218 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-30149 1 Open-emr 1 Openemr 2026-06-17 N/A 6.4 MEDIUM
OpenEMR is a free and open source electronic health records and medical practice management application. OpenEMR allows reflected cross-site scripting (XSS) in the AJAX Script interface\super\layout_listitems_ajax.php via the target parameter. This vulnerability is fixed in 7.0.3.
CVE-2025-29789 1 Open-emr 1 Openemr 2026-06-17 N/A 7.5 HIGH
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.3.0 are vulnerable to Directory Traversal in the Load Code feature. Version 7.3.0 contains a patch for the issue.
CVE-2025-29772 1 Open-emr 1 Openemr 2026-06-17 N/A 6.1 MEDIUM
OpenEMR is a free and open source electronic health records and medical practice management application. The POST parameter hidden_subcategory is output to the page without being properly processed. This leads to a reflected cross-site scripting (XSS) vul;nerability in CAMOS new.php. This vulnerability is fixed in 7.0.3.
CVE-2024-37734 1 Open-emr 1 Openemr 2026-06-17 N/A 9.8 CRITICAL
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
CVE-2024-26476 1 Open-emr 1 Openemr 2026-06-17 N/A 3.5 LOW
An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component.
CVE-2024-22611 1 Open-emr 1 Openemr 2026-06-17 N/A 9.8 CRITICAL
OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.
CVE-2024-0875 1 Open-emr 1 Openemr 2026-06-17 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging feature, which can then be sent to other users. When the recipient views the malicious message, the payload is executed, potentially compromising their account. This issue is fixed in version 7.0.2.1.
CVE-2023-54347 1 Open-emr 1 Openemr 2026-06-17 N/A 7.5 HIGH
OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protections by sending repeated login attempts to the main login endpoint. Attackers can submit POST requests with authUser and clearPass parameters to systematically test username and password combinations without account lockout restrictions.
CVE-2023-2950 1 Open-emr 1 Openemr 2026-06-17 N/A 8.1 HIGH
Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2949 1 Open-emr 1 Openemr 2026-06-17 N/A 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2948 1 Open-emr 1 Openemr 2026-06-17 N/A 6.1 MEDIUM
Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2947 1 Open-emr 1 Openemr 2026-06-17 N/A 4.8 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2946 1 Open-emr 1 Openemr 2026-06-17 N/A 8.1 HIGH
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2945 1 Open-emr 1 Openemr 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2944 1 Open-emr 1 Openemr 2026-06-17 N/A 5.4 MEDIUM
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2943 1 Open-emr 1 Openemr 2026-06-17 N/A 8.8 HIGH
Code Injection in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2942 1 Open-emr 1 Openemr 2026-06-17 N/A 8.1 HIGH
Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2674 1 Open-emr 1 Openemr 2026-06-17 N/A 4.3 MEDIUM
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2566 1 Open-emr 1 Openemr 2026-06-17 N/A 4.8 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-22974 1 Open-emr 1 Openemr 2026-06-17 N/A 7.5 HIGH
A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.