CVE-2026-32125
- EPSS 0.16%
- Veröffentlicht 11.03.2026 20:51:32
- Zuletzt bearbeitet 13.03.2026 15:47:01
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, track/item names from the Track Anything feature are stored from user input (POST) and later rendered in Dygraph charts (titles...
CVE-2026-32124
- EPSS 0.16%
- Veröffentlicht 11.03.2026 20:50:41
- Zuletzt bearbeitet 13.03.2026 15:47:23
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the dynamic code picker AJAX endpoint returns code descriptions (code_text) that are rendered in the front end (e.g. DataTables...
CVE-2026-32123
- EPSS 0.25%
- Veröffentlicht 11.03.2026 20:49:38
- Zuletzt bearbeitet 13.03.2026 15:47:50
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, sensitivity checks for group encounters are broken because the code only consults form_encounter for sensitivity, while group e...
CVE-2026-32122
- EPSS 0.23%
- Veröffentlicht 11.03.2026 20:48:26
- Zuletzt bearbeitet 13.03.2026 15:48:07
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the Claim File Tracker feature exposes an AJAX endpoint that returns billing claim metadata (claim IDs, payer info, transmissio...
CVE-2026-32121
- EPSS 0.19%
- Veröffentlicht 11.03.2026 20:47:31
- Zuletzt bearbeitet 13.03.2026 15:49:20
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, Stored XSS in prescription CSS/HTML print view via patient demographics. That finding involves server-side rendering of patien...
- EPSS 0.28%
- Veröffentlicht 11.03.2026 20:46:19
- Zuletzt bearbeitet 13.03.2026 15:49:56
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, stored cross-site scripting (XSS) in the Graphical Pain Map ("clickmap") form allows any authenticated clinician to inject arbi...
CVE-2026-24848
- EPSS 6.49%
- Veröffentlicht 03.03.2026 22:16:28
- Zuletzt bearbeitet 04.03.2026 21:58:33
OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and earlier, the disposeDocument() method in EtherFaxActions.php allows authenticated users to write arbitrary content to arbitrary loca...
CVE-2026-24898
- EPSS 0.56%
- Veröffentlicht 03.03.2026 22:16:28
- Zuletzt bearbeitet 04.03.2026 21:57:13
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx callback endpoint allows any unauthenticated visitor to obtain the...
CVE-2026-25146
- EPSS 0.44%
- Veröffentlicht 03.03.2026 22:16:28
- Zuletzt bearbeitet 04.03.2026 21:56:00
OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These s...
CVE-2026-25147
- EPSS 0.22%
- Veröffentlicht 27.02.2026 16:44:40
- Zuletzt bearbeitet 03.03.2026 19:10:32
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, in `portal/portal_payment.php`, the patient id used for the page is taken from the request (`$pid = $_REQUEST['pid'] ?? $...