CVE-2025-30149
- EPSS 0.63%
- Veröffentlicht 31.03.2025 16:15:25
- Zuletzt bearbeitet 30.04.2025 16:08:29
OpenEMR is a free and open source electronic health records and medical practice management application. OpenEMR allows reflected cross-site scripting (XSS) in the AJAX Script interface\super\layout_listitems_ajax.php via the target parameter. This v...
CVE-2025-30161
- EPSS 0.5%
- Veröffentlicht 31.03.2025 16:15:25
- Zuletzt bearbeitet 13.05.2025 13:36:27
OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vulnerability in the Bronchitis form component of OpenEMR allows anyone who is able to edit a bronchitis form to steal credentials f...
CVE-2025-29772
- EPSS 0.68%
- Veröffentlicht 31.03.2025 16:15:24
- Zuletzt bearbeitet 13.05.2025 13:36:30
OpenEMR is a free and open source electronic health records and medical practice management application. The POST parameter hidden_subcategory is output to the page without being properly processed. This leads to a reflected cross-site scripting (XSS...
CVE-2025-29789
- EPSS 0.18%
- Veröffentlicht 25.03.2025 20:29:29
- Zuletzt bearbeitet 06.05.2025 19:26:56
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.3.0 are vulnerable to Directory Traversal in the Load Code feature. Version 7.3.0 contains a patch for the issue.
CVE-2024-0875
- EPSS 4.57%
- Veröffentlicht 15.11.2024 11:15:09
- Zuletzt bearbeitet 19.11.2024 16:03:56
A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging feature, which can then be sent to other users. When the recipient...
CVE-2024-37734
- EPSS 3.71%
- Veröffentlicht 26.06.2024 22:15:10
- Zuletzt bearbeitet 01.05.2025 19:38:20
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
CVE-2024-26476
- EPSS 0.05%
- Veröffentlicht 28.02.2024 22:15:26
- Zuletzt bearbeitet 13.05.2025 14:41:53
An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component.
CVE-2023-2950
- EPSS 0.45%
- Veröffentlicht 28.05.2023 04:15:14
- Zuletzt bearbeitet 21.11.2024 07:59:37
Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2949
- EPSS 74.33%
- Veröffentlicht 28.05.2023 04:15:13
- Zuletzt bearbeitet 21.11.2024 07:59:37
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2948
- EPSS 84.4%
- Veröffentlicht 28.05.2023 04:15:12
- Zuletzt bearbeitet 21.11.2024 07:59:37
Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.