Open-emr

Openemr

218 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.16%
  • Veröffentlicht 19.03.2026 19:41:47
  • Zuletzt bearbeitet 20.03.2026 16:20:15

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, DOM-based stored XSS in the jQuery SearchHighlight plugin (`library/js/SearchHighlight.js`) allows an authenticated user with e...

Exploit
  • EPSS 1.89%
  • Veröffentlicht 19.03.2026 19:30:53
  • Zuletzt bearbeitet 20.03.2026 19:16:15

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command injection vulnerability in the backup functionality that can be exploited by authenticated attackers....

Exploit
  • EPSS 0.55%
  • Veröffentlicht 19.03.2026 19:27:17
  • Zuletzt bearbeitet 20.03.2026 17:18:35

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the DICOM zip/export feature uses a user-supplied destination or path component when creating the zip file, without sanitizing ...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 19.03.2026 19:25:56
  • Zuletzt bearbeitet 20.03.2026 17:19:12

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the encounter vitals API accepts an `id` in the request body and treats it as an UPDATE. There is no verification that the vita...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 18.03.2026 20:30:30
  • Zuletzt bearbeitet 20.03.2026 19:16:13

OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the message/note update endpoint (e.g. PUT or POST) updates by message/note ID only and does not verify th...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 11.03.2026 20:53:09
  • Zuletzt bearbeitet 13.03.2026 15:44:50

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, OpenEMR contains a SQL injection vulnerability in the ajax graphs library that can be exploited by authenticated attackers. The...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 11.03.2026 20:52:16
  • Zuletzt bearbeitet 13.03.2026 15:46:41

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, an inverted boolean condition in ControllerRouter::route() causes the admin/super ACL check to be enforced only for controllers...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 11.03.2026 20:51:32
  • Zuletzt bearbeitet 13.03.2026 15:47:01

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, track/item names from the Track Anything feature are stored from user input (POST) and later rendered in Dygraph charts (titles...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 11.03.2026 20:50:41
  • Zuletzt bearbeitet 13.03.2026 15:47:23

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the dynamic code picker AJAX endpoint returns code descriptions (code_text) that are rendered in the front end (e.g. DataTables...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 11.03.2026 20:49:38
  • Zuletzt bearbeitet 13.03.2026 15:47:50

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, sensitivity checks for group encounters are broken because the code only consults form_encounter for sensitivity, while group e...