CVE-2026-33917
- EPSS 0.45%
- Veröffentlicht 25.03.2026 23:31:20
- Zuletzt bearbeitet 26.03.2026 16:26:36
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contais a SQL injection vulnerability in the ajax_save CAMOS form that can be exploited by authenticated attackers. The...
CVE-2026-33915
- EPSS 0.23%
- Veröffentlicht 25.03.2026 23:23:40
- Zuletzt bearbeitet 26.03.2026 16:26:16
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, five insurance company REST API routes are missing the `RestConfig::request_authorization_check()` call that every othe...
CVE-2026-33914
- EPSS 0.43%
- Veröffentlicht 25.03.2026 23:13:16
- Zuletzt bearbeitet 26.03.2026 18:34:17
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the PostCalendar module contains a blind SQL injection vulnerability in the `categoriesUpdate` administrative function....
CVE-2026-33913
- EPSS 0.29%
- Veröffentlicht 25.03.2026 22:52:50
- Zuletzt bearbeitet 26.03.2026 16:25:24
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted CCDA document containing `<xi:inc...
CVE-2026-33912
- EPSS 0.22%
- Veröffentlicht 25.03.2026 22:51:15
- Zuletzt bearbeitet 26.03.2026 16:24:01
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated attacker could craft a malicious form that, when submitted by a victim, executes arbitrary JavaScript ...
CVE-2026-33911
- EPSS 0.23%
- Veröffentlicht 25.03.2026 22:44:13
- Zuletzt bearbeitet 26.03.2026 16:23:28
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the POST parameter `title` is reflected back in a JSON response built with `json_encode()`. Because the response is ser...
CVE-2026-33910
- EPSS 0.43%
- Veröffentlicht 25.03.2026 22:41:02
- Zuletzt bearbeitet 26.03.2026 16:19:40
OpenEMR is a free and open source electronic health records and medical practice management application. Versions up to and including 8.0.0.2 contain a SQL injection vulnerability in the patient selection feature that can be exploited by authenticate...
CVE-2026-33909
- EPSS 0.33%
- Veröffentlicht 25.03.2026 22:35:29
- Zuletzt bearbeitet 26.03.2026 18:02:01
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, several variables in the MedEx recall/reminder processing code are concatenated directly into SQL queries without param...
CVE-2026-33348
- EPSS 0.3%
- Veröffentlicht 25.03.2026 22:30:37
- Zuletzt bearbeitet 26.03.2026 18:02:20
OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form are displayed on the encounter...
CVE-2026-32120
- EPSS 0.25%
- Veröffentlicht 25.03.2026 22:27:38
- Zuletzt bearbeitet 26.03.2026 18:03:30
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the fee sheet product save logic (`library/FeeSheet.class.p...