CVE-2026-24848
- EPSS 0.21%
- Veröffentlicht 03.03.2026 22:16:28
- Zuletzt bearbeitet 04.03.2026 21:58:33
OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and earlier, the disposeDocument() method in EtherFaxActions.php allows authenticated users to write arbitrary content to arbitrary loca...
CVE-2026-24898
- EPSS 0.19%
- Veröffentlicht 03.03.2026 22:16:28
- Zuletzt bearbeitet 04.03.2026 21:57:13
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx callback endpoint allows any unauthenticated visitor to obtain the...
CVE-2026-25146
- EPSS 0.04%
- Veröffentlicht 03.03.2026 22:16:28
- Zuletzt bearbeitet 04.03.2026 21:56:00
OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These s...
CVE-2026-25147
- EPSS 0.1%
- Veröffentlicht 27.02.2026 16:44:40
- Zuletzt bearbeitet 03.03.2026 19:10:32
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, in `portal/portal_payment.php`, the patient id used for the page is taken from the request (`$pid = $_REQUEST['pid'] ?? $...
CVE-2026-24488
- EPSS 0.01%
- Veröffentlicht 27.02.2026 16:41:45
- Zuletzt bearbeitet 03.03.2026 18:48:01
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, an arbitrary file exfiltration vulnerability in the fax sending endpoint allows any authenticated user to ...
CVE-2026-27943
- EPSS 0.1%
- Veröffentlicht 26.02.2026 01:30:31
- Zuletzt bearbeitet 27.02.2026 14:51:27
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the eye exam (eye_mag) view loads data by `form_id` (or equivalent) without verifying that the form belong...
CVE-2026-25930
- EPSS 0.1%
- Veröffentlicht 25.02.2026 18:48:10
- Zuletzt bearbeitet 27.02.2026 14:38:24
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Layout-Based Form (LBF) printable view accepts `formid` and `visitid` (or `patientid`) from the request and does not ...
CVE-2026-25929
- EPSS 0.1%
- Veröffentlicht 25.02.2026 18:46:44
- Zuletzt bearbeitet 27.02.2026 14:39:26
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the document controller’s `patient_picture` context serves the patient’s photo by document ID or patient ID without verif...
CVE-2026-25927
- EPSS 0.1%
- Veröffentlicht 25.02.2026 18:43:25
- Zuletzt bearbeitet 27.02.2026 14:40:46
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the DICOM viewer state API (e.g. upload or state save/load) accepts a document ID (`doc_id`) without verifying that the ...
CVE-2026-25746
- EPSS 0%
- Veröffentlicht 25.02.2026 18:39:24
- Zuletzt bearbeitet 27.02.2026 14:40:01
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 contain a SQL injection vulnerability in prescription that can be exploited by authenticated attackers. The vulnerability...