CVE-2026-32119
- EPSS 0.16%
- Veröffentlicht 19.03.2026 19:41:47
- Zuletzt bearbeitet 20.03.2026 16:20:15
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, DOM-based stored XSS in the jQuery SearchHighlight plugin (`library/js/SearchHighlight.js`) allows an authenticated user with e...
CVE-2026-32238
- EPSS 1.89%
- Veröffentlicht 19.03.2026 19:30:53
- Zuletzt bearbeitet 20.03.2026 19:16:15
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command injection vulnerability in the backup functionality that can be exploited by authenticated attackers....
CVE-2026-25928
- EPSS 0.55%
- Veröffentlicht 19.03.2026 19:27:17
- Zuletzt bearbeitet 20.03.2026 17:18:35
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the DICOM zip/export feature uses a user-supplied destination or path component when creating the zip file, without sanitizing ...
CVE-2026-25744
- EPSS 0.22%
- Veröffentlicht 19.03.2026 19:25:56
- Zuletzt bearbeitet 20.03.2026 17:19:12
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the encounter vitals API accepts an `id` in the request body and treats it as an UPDATE. There is no verification that the vita...
CVE-2026-25745
- EPSS 0.27%
- Veröffentlicht 18.03.2026 20:30:30
- Zuletzt bearbeitet 20.03.2026 19:16:13
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the message/note update endpoint (e.g. PUT or POST) updates by message/note ID only and does not verify th...
CVE-2026-32127
- EPSS 0.33%
- Veröffentlicht 11.03.2026 20:53:09
- Zuletzt bearbeitet 13.03.2026 15:44:50
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, OpenEMR contains a SQL injection vulnerability in the ajax graphs library that can be exploited by authenticated attackers. The...
CVE-2026-32126
- EPSS 0.26%
- Veröffentlicht 11.03.2026 20:52:16
- Zuletzt bearbeitet 13.03.2026 15:46:41
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, an inverted boolean condition in ControllerRouter::route() causes the admin/super ACL check to be enforced only for controllers...
CVE-2026-32125
- EPSS 0.16%
- Veröffentlicht 11.03.2026 20:51:32
- Zuletzt bearbeitet 13.03.2026 15:47:01
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, track/item names from the Track Anything feature are stored from user input (POST) and later rendered in Dygraph charts (titles...
CVE-2026-32124
- EPSS 0.16%
- Veröffentlicht 11.03.2026 20:50:41
- Zuletzt bearbeitet 13.03.2026 15:47:23
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the dynamic code picker AJAX endpoint returns code descriptions (code_text) that are rendered in the front end (e.g. DataTables...
CVE-2026-32123
- EPSS 0.25%
- Veröffentlicht 11.03.2026 20:49:38
- Zuletzt bearbeitet 13.03.2026 15:47:50
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, sensitivity checks for group encounters are broken because the code only consults form_encounter for sensitivity, while group e...