- EPSS 0.16%
- Veröffentlicht 25.02.2026 01:13:28
- Zuletzt bearbeitet 25.02.2026 17:00:23
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, when a link is sent via Secure Messaging, clicking the link opens the website within the OpenEMR/Portal site. This behavi...
CVE-2025-67752
- EPSS 0.23%
- Veröffentlicht 25.02.2026 01:09:20
- Zuletzt bearbeitet 25.02.2026 16:58:43
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default (`verify: f...
CVE-2025-67491
- EPSS 0.25%
- Veröffentlicht 25.02.2026 00:31:11
- Zuletzt bearbeitet 25.02.2026 17:01:48
OpenEMR is a free and open source electronic health records and medical practice management application. Versions 5.0.0.5 through 7.0.3.4 have a stored cross-site scripting vulnerability in the ub04 helper of the billing interface. The variable `$dat...
CVE-2025-67645
- EPSS 0.33%
- Veröffentlicht 27.01.2026 23:20:18
- Zuletzt bearbeitet 12.02.2026 20:50:17
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access control in the Profile Edit endpoint. An authenticated normal user can modify the request parameters...
CVE-2025-54373
- EPSS 0.37%
- Veröffentlicht 27.01.2026 23:11:57
- Zuletzt bearbeitet 12.02.2026 20:58:12
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a vulnerability where sensitive data is unintentionally revealed to unauthorized parties. Contents of Clinical Notes...
CVE-2021-47817
- EPSS 0.67%
- Veröffentlicht 21.01.2026 17:27:33
- Zuletzt bearbeitet 26.05.2026 00:16:45
OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers can chain with a file upload to achieve remote code execution. Attackers can exploit the vulnerability by crafting a malicious paylo...
CVE-2013-10044
- EPSS 1.28%
- Veröffentlicht 01.08.2025 20:46:45
- Zuletzt bearbeitet 26.11.2025 14:10:49
An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalate privileges. Once elevated, the attacker can exploit an unrestricted f...
CVE-2025-43860
- EPSS 3.43%
- Veröffentlicht 23.05.2025 15:35:01
- Zuletzt bearbeitet 02.07.2025 00:36:14
OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.3.4 allows any authenticated user with patient creation and editing pr...
CVE-2025-32967
- EPSS 0.24%
- Veröffentlicht 23.05.2025 15:31:52
- Zuletzt bearbeitet 02.07.2025 00:41:37
OpenEMR is a free and open source electronic health records and medical practice management application. A logging oversight in versions prior to 7.0.3.4 allows password change events to go unrecorded on the client-side log viewer, preventing adminis...
CVE-2025-32794
- EPSS 4.05%
- Veröffentlicht 23.05.2025 15:15:32
- Zuletzt bearbeitet 02.07.2025 00:45:22
OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.3.4 allows any authenticated user with patient creation privileges to ...