CVE-2026-67611
- EPSS 0.33%
- Veröffentlicht 03.08.2026 16:04:34
- Zuletzt bearbeitet 01.09.2026 15:36:44
OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client regist...
CVE-2026-39932
- EPSS 0.77%
- Veröffentlicht 03.08.2026 16:00:09
- Zuletzt bearbeitet 01.09.2026 15:36:55
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP pay...
CVE-2026-39931
- EPSS 0.33%
- Veröffentlicht 03.08.2026 15:54:13
- Zuletzt bearbeitet 01.09.2026 15:37:05
OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to execute arbitrary DDL and DML statements against the application d...
CVE-2026-46518
- EPSS 0.21%
- Veröffentlicht 09.06.2026 22:50:49
- Zuletzt bearbeitet 23.07.2026 09:10:00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-site scripting vulnerability in the prescription CSS/HTML multi-print feature allows a patient portal us...
CVE-2023-54347
- EPSS 0.54%
- Veröffentlicht 05.05.2026 12:16:17
- Zuletzt bearbeitet 05.05.2026 20:00:28
OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protections by sending repeated login attempts to the main login endpoint. Attackers can submit POST requests with authUser and clearPass...
CVE-2026-34056
- EPSS 0.27%
- Veröffentlicht 25.03.2026 23:53:15
- Zuletzt bearbeitet 26.03.2026 16:15:22
OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access Control vulnerability in OpenEMR up to and including version 8.0.0.3 allows low-privilege users to view and download Ensora eRx e...
CVE-2026-34055
- EPSS 0.27%
- Veröffentlicht 25.03.2026 23:49:06
- Zuletzt bearbeitet 26.03.2026 16:16:58
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient notes functions in `library/pnotes.inc.php` perform updates and deletes using `WHERE id = ?` without...
CVE-2026-34053
- EPSS 0.42%
- Veröffentlicht 25.03.2026 23:46:21
- Zuletzt bearbeitet 26.03.2026 16:17:22
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the AJAX deletion endpoint `interface/forms/procedure_order/handle_deletions.php` allows any a...
CVE-2026-34051
- EPSS 0.22%
- Veröffentlicht 25.03.2026 23:45:06
- Zuletzt bearbeitet 26.03.2026 16:17:42
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper access control on the Import/Export functionality, allowing unauthorized users to perform import and e...
CVE-2026-33934
- EPSS 0.24%
- Veröffentlicht 25.03.2026 23:41:51
- Zuletzt bearbeitet 26.03.2026 16:28:33
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have a missing authorization check in `portal/sign/lib/show-signature.php` that allows any authenticated patient portal...