CVE-2026-33321
- EPSS 0.28%
- Veröffentlicht 19.03.2026 20:20:37
- Zuletzt bearbeitet 20.03.2026 15:03:34
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be print...
CVE-2026-33301
- EPSS 0.44%
- Veröffentlicht 19.03.2026 20:10:43
- Zuletzt bearbeitet 20.03.2026 16:16:47
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be prin...
CVE-2026-33299
- EPSS 0.17%
- Veröffentlicht 19.03.2026 20:07:58
- Zuletzt bearbeitet 20.03.2026 16:17:24
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill **Eye Exam** forms in patient encounters. The answers to the form are disp...
CVE-2026-32119
- EPSS 0.16%
- Veröffentlicht 19.03.2026 19:41:47
- Zuletzt bearbeitet 20.03.2026 16:20:15
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, DOM-based stored XSS in the jQuery SearchHighlight plugin (`library/js/SearchHighlight.js`) allows an authenticated user with e...
CVE-2026-32238
- EPSS 1.89%
- Veröffentlicht 19.03.2026 19:30:53
- Zuletzt bearbeitet 20.03.2026 19:16:15
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command injection vulnerability in the backup functionality that can be exploited by authenticated attackers....
CVE-2026-25928
- EPSS 0.55%
- Veröffentlicht 19.03.2026 19:27:17
- Zuletzt bearbeitet 20.03.2026 17:18:35
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the DICOM zip/export feature uses a user-supplied destination or path component when creating the zip file, without sanitizing ...
CVE-2026-25744
- EPSS 0.22%
- Veröffentlicht 19.03.2026 19:25:56
- Zuletzt bearbeitet 20.03.2026 17:19:12
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the encounter vitals API accepts an `id` in the request body and treats it as an UPDATE. There is no verification that the vita...
CVE-2026-25745
- EPSS 0.27%
- Veröffentlicht 18.03.2026 20:30:30
- Zuletzt bearbeitet 20.03.2026 19:16:13
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the message/note update endpoint (e.g. PUT or POST) updates by message/note ID only and does not verify th...
CVE-2026-32127
- EPSS 0.33%
- Veröffentlicht 11.03.2026 20:53:09
- Zuletzt bearbeitet 13.03.2026 15:44:50
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, OpenEMR contains a SQL injection vulnerability in the ajax graphs library that can be exploited by authenticated attackers. The...
CVE-2026-32126
- EPSS 0.26%
- Veröffentlicht 11.03.2026 20:52:16
- Zuletzt bearbeitet 13.03.2026 15:46:41
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, an inverted boolean condition in ControllerRouter::route() causes the admin/super ACL check to be enforced only for controllers...