Open-emr

Openemr

221 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.27%
  • Veröffentlicht 25.03.2026 23:40:16
  • Zuletzt bearbeitet 26.03.2026 16:17:56

OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to version 8.0.0.3, a reflected cross-site scripting (XSS) vulnerability in the custom template editor allo...

  • EPSS 0.19%
  • Veröffentlicht 25.03.2026 23:37:58
  • Zuletzt bearbeitet 26.03.2026 16:27:53

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-site scripting vulnerability in the CCDA document preview allows an attacker who can upload or send a CC...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 25.03.2026 23:36:48
  • Zuletzt bearbeitet 26.03.2026 16:29:06

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment page allows any authenticated po...

  • EPSS 0.24%
  • Veröffentlicht 25.03.2026 23:35:06
  • Zuletzt bearbeitet 26.03.2026 16:27:29

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-download endpoint `interface/billing/get_claim_file.php` only verifies that the caller has a valid ses...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 25.03.2026 23:31:20
  • Zuletzt bearbeitet 26.03.2026 16:26:36

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contais a SQL injection vulnerability in the ajax_save CAMOS form that can be exploited by authenticated attackers. The...

  • EPSS 0.23%
  • Veröffentlicht 25.03.2026 23:23:40
  • Zuletzt bearbeitet 26.03.2026 16:26:16

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, five insurance company REST API routes are missing the `RestConfig::request_authorization_check()` call that every othe...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 25.03.2026 23:13:16
  • Zuletzt bearbeitet 26.03.2026 18:34:17

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the PostCalendar module contains a blind SQL injection vulnerability in the `categoriesUpdate` administrative function....

Exploit
  • EPSS 0.29%
  • Veröffentlicht 25.03.2026 22:52:50
  • Zuletzt bearbeitet 26.03.2026 16:25:24

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted CCDA document containing `<xi:inc...

  • EPSS 0.22%
  • Veröffentlicht 25.03.2026 22:51:15
  • Zuletzt bearbeitet 26.03.2026 16:24:01

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated attacker could craft a malicious form that, when submitted by a victim, executes arbitrary JavaScript ...

  • EPSS 0.23%
  • Veröffentlicht 25.03.2026 22:44:13
  • Zuletzt bearbeitet 26.03.2026 16:23:28

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the POST parameter `title` is reflected back in a JSON response built with `json_encode()`. Because the response is ser...