Openemr

Openemr

91 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.02%
  • Veröffentlicht 25.03.2026 23:53:15
  • Zuletzt bearbeitet 26.03.2026 16:15:22

OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access Control vulnerability in OpenEMR up to and including version 8.0.0.3 allows low-privilege users to view and download Ensora eRx e...

  • EPSS 0.02%
  • Veröffentlicht 25.03.2026 23:49:06
  • Zuletzt bearbeitet 26.03.2026 16:16:58

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient notes functions in `library/pnotes.inc.php` perform updates and deletes using `WHERE id = ?` without...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 25.03.2026 23:46:21
  • Zuletzt bearbeitet 26.03.2026 16:17:22

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the AJAX deletion endpoint `interface/forms/procedure_order/handle_deletions.php` allows any a...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 25.03.2026 23:45:06
  • Zuletzt bearbeitet 26.03.2026 16:17:42

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper access control on the Import/Export functionality, allowing unauthorized users to perform import and e...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 25.03.2026 23:41:51
  • Zuletzt bearbeitet 26.03.2026 16:28:33

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have a missing authorization check in `portal/sign/lib/show-signature.php` that allows any authenticated patient portal...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 25.03.2026 23:40:16
  • Zuletzt bearbeitet 26.03.2026 16:17:56

OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to version 8.0.0.3, a reflected cross-site scripting (XSS) vulnerability in the custom template editor allo...

  • EPSS 0.03%
  • Veröffentlicht 25.03.2026 23:37:58
  • Zuletzt bearbeitet 26.03.2026 16:27:53

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-site scripting vulnerability in the CCDA document preview allows an attacker who can upload or send a CC...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 25.03.2026 23:36:48
  • Zuletzt bearbeitet 26.03.2026 16:29:06

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment page allows any authenticated po...

  • EPSS 0.04%
  • Veröffentlicht 25.03.2026 23:35:06
  • Zuletzt bearbeitet 26.03.2026 16:27:29

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-download endpoint `interface/billing/get_claim_file.php` only verifies that the caller has a valid ses...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 25.03.2026 23:31:20
  • Zuletzt bearbeitet 26.03.2026 16:26:36

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contais a SQL injection vulnerability in the ajax_save CAMOS form that can be exploited by authenticated attackers. The...