CVE-2026-25928
- EPSS 0.02%
- Veröffentlicht 19.03.2026 19:27:17
- Zuletzt bearbeitet 20.03.2026 17:18:35
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the DICOM zip/export feature uses a user-supplied destination or path component when creating the zip file, without sanitizing ...
CVE-2026-25744
- EPSS 0.1%
- Veröffentlicht 19.03.2026 19:25:56
- Zuletzt bearbeitet 20.03.2026 17:19:12
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the encounter vitals API accepts an `id` in the request body and treats it as an UPDATE. There is no verification that the vita...
CVE-2026-25745
- EPSS 0.02%
- Veröffentlicht 18.03.2026 20:30:30
- Zuletzt bearbeitet 20.03.2026 19:16:13
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the message/note update endpoint (e.g. PUT or POST) updates by message/note ID only and does not verify th...
CVE-2026-32127
- EPSS 0%
- Veröffentlicht 11.03.2026 20:53:09
- Zuletzt bearbeitet 13.03.2026 15:44:50
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, OpenEMR contains a SQL injection vulnerability in the ajax graphs library that can be exploited by authenticated attackers. The...
CVE-2026-32126
- EPSS 0.13%
- Veröffentlicht 11.03.2026 20:52:16
- Zuletzt bearbeitet 13.03.2026 15:46:41
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, an inverted boolean condition in ControllerRouter::route() causes the admin/super ACL check to be enforced only for controllers...
CVE-2026-32125
- EPSS 0.2%
- Veröffentlicht 11.03.2026 20:51:32
- Zuletzt bearbeitet 13.03.2026 15:47:01
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, track/item names from the Track Anything feature are stored from user input (POST) and later rendered in Dygraph charts (titles...
CVE-2026-32124
- EPSS 0.05%
- Veröffentlicht 11.03.2026 20:50:41
- Zuletzt bearbeitet 13.03.2026 15:47:23
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the dynamic code picker AJAX endpoint returns code descriptions (code_text) that are rendered in the front end (e.g. DataTables...
CVE-2026-32123
- EPSS 0.11%
- Veröffentlicht 11.03.2026 20:49:38
- Zuletzt bearbeitet 13.03.2026 15:47:50
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, sensitivity checks for group encounters are broken because the code only consults form_encounter for sensitivity, while group e...
CVE-2026-32122
- EPSS 0.09%
- Veröffentlicht 11.03.2026 20:48:26
- Zuletzt bearbeitet 13.03.2026 15:48:07
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the Claim File Tracker feature exposes an AJAX endpoint that returns billing claim metadata (claim IDs, payer info, transmissio...
CVE-2026-32121
- EPSS 0.2%
- Veröffentlicht 11.03.2026 20:47:31
- Zuletzt bearbeitet 13.03.2026 15:49:20
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, Stored XSS in prescription CSS/HTML print view via patient demographics. That finding involves server-side rendering of patien...