Vulnerabilities (CVE)

Filtered by vendor Open-emr Subscribe
Total 218 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25041 1 Open-emr 1 Openemr 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
OpenEMR v6.0.0 was discovered to contain an incorrect access control issue.
CVE-2022-24643 1 Open-emr 1 Openemr 2026-06-17 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) issue was discovered in the OpenEMR Hospital Information Management System version 6.0.0.
CVE-2022-1461 1 Open-emr 1 Openemr 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2022-1459 1 Open-emr 1 Openemr 2026-06-17 5.5 MEDIUM 8.3 HIGH
Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2022-1458 1 Open-emr 1 Openemr 2026-06-17 3.5 LOW 5.4 MEDIUM
Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2022-1181 1 Open-emr 1 Openemr 2026-06-17 3.5 LOW 5.4 MEDIUM
Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2.
CVE-2022-1180 1 Open-emr 1 Openemr 2026-06-17 3.5 LOW 3.5 LOW
Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
CVE-2022-1179 1 Open-emr 1 Openemr 2026-06-17 3.5 LOW 5.4 MEDIUM
Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
CVE-2022-1178 1 Open-emr 1 Openemr 2026-06-17 3.5 LOW 5.4 MEDIUM
Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
CVE-2022-1177 1 Open-emr 1 Openemr 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
CVE-2021-47817 1 Open-emr 1 Openemr 2026-06-17 N/A 5.4 MEDIUM
OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers can chain with a file upload to achieve remote code execution. Attackers can exploit the vulnerability by crafting a malicious payload to download and execute a web shell, enabling remote command execution on the vulnerable OpenEMR instance.
CVE-2021-41843 1 Open-emr 1 Openemr 2026-06-17 6.8 MEDIUM 6.5 MEDIUM
An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables of the database via the parameter provider_id, as demonstrated by the /interface/main/calendar/index.php?module=PostCalendar&func=search URI.
CVE-2021-40352 1 Open-emr 1 Openemr 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.
CVE-2021-32104 1 Open-emr 1 Openemr 2026-06-17 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability exists (with user privileges) in interface/forms/eye_mag/save.php in OpenEMR 5.0.2.1.
CVE-2021-32103 1 Open-emr 1 Openemr 2026-06-17 3.5 LOW 4.8 MEDIUM
A Stored XSS vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.1 allows a admin authenticated user to inject arbitrary web script or HTML via the lname parameter.
CVE-2021-32102 1 Open-emr 1 Openemr 2026-06-17 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1.
CVE-2021-32101 1 Open-emr 1 Openemr 2026-06-17 6.4 MEDIUM 8.2 HIGH
The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the attacker can then manipulate and read data of every registered patient.
CVE-2021-25923 1 Open-emr 1 Openemr 2026-06-17 6.8 MEDIUM 8.1 HIGH
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.
CVE-2021-25922 1 Open-emr 1 Openemr 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code.
CVE-2021-25921 1 Open-emr 1 Openemr 2026-06-17 3.5 LOW 5.4 MEDIUM
In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker could lure an admin to enter a malicious payload and by that initiate the exploit.