Open-emr

Openemr

221 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.18%
  • Veröffentlicht 25.02.2026 01:34:35
  • Zuletzt bearbeitet 26.02.2026 15:33:56

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Eye Exam form module allows any authenticated user to be redirected to an arbitrary external URL. This can be exploit...

  • EPSS 0.14%
  • Veröffentlicht 25.02.2026 01:23:22
  • Zuletzt bearbeitet 26.02.2026 15:34:11

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the `xl()` translation function returns unescaped strings. While wrapper functions exist for escaping in different contex...

Exploit
  • EPSS 3.61%
  • Veröffentlicht 25.02.2026 01:18:14
  • Zuletzt bearbeitet 25.02.2026 17:01:10

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a stored cross-site scripting vulnerability in the GAD-7 anxiety assessment form allows authenticated users with clinicia...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 25.02.2026 01:13:28
  • Zuletzt bearbeitet 25.02.2026 17:00:23

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, when a link is sent via Secure Messaging, clicking the link opens the website within the OpenEMR/Portal site. This behavi...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 25.02.2026 01:09:20
  • Zuletzt bearbeitet 25.02.2026 16:58:43

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default (`verify: f...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 25.02.2026 00:31:11
  • Zuletzt bearbeitet 25.02.2026 17:01:48

OpenEMR is a free and open source electronic health records and medical practice management application. Versions 5.0.0.5 through 7.0.3.4 have a stored cross-site scripting vulnerability in the ub04 helper of the billing interface. The variable `$dat...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 27.01.2026 23:20:18
  • Zuletzt bearbeitet 12.02.2026 20:50:17

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access control in the Profile Edit endpoint. An authenticated normal user can modify the request parameters...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 27.01.2026 23:11:57
  • Zuletzt bearbeitet 12.02.2026 20:58:12

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a vulnerability where sensitive data is unintentionally revealed to unauthorized parties. Contents of Clinical Notes...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 21.01.2026 17:27:33
  • Zuletzt bearbeitet 26.05.2026 00:16:45

OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers can chain with a file upload to achieve remote code execution. Attackers can exploit the vulnerability by crafting a malicious paylo...

Exploit
  • EPSS 1.34%
  • Veröffentlicht 01.08.2025 20:46:45
  • Zuletzt bearbeitet 26.11.2025 14:10:49

An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalate privileges. Once elevated, the attacker can exploit an unrestricted f...