CVE-2026-33915
- EPSS 0.03%
- Veröffentlicht 25.03.2026 23:23:40
- Zuletzt bearbeitet 26.03.2026 16:26:16
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, five insurance company REST API routes are missing the `RestConfig::request_authorization_check()` call that every othe...
CVE-2026-33914
- EPSS 0.03%
- Veröffentlicht 25.03.2026 23:13:16
- Zuletzt bearbeitet 26.03.2026 18:34:17
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the PostCalendar module contains a blind SQL injection vulnerability in the `categoriesUpdate` administrative function....
CVE-2026-33913
- EPSS 0.05%
- Veröffentlicht 25.03.2026 22:52:50
- Zuletzt bearbeitet 26.03.2026 16:25:24
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted CCDA document containing `<xi:inc...
CVE-2026-33912
- EPSS 0.03%
- Veröffentlicht 25.03.2026 22:51:15
- Zuletzt bearbeitet 26.03.2026 16:24:01
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated attacker could craft a malicious form that, when submitted by a victim, executes arbitrary JavaScript ...
CVE-2026-33911
- EPSS 0.03%
- Veröffentlicht 25.03.2026 22:44:13
- Zuletzt bearbeitet 26.03.2026 16:23:28
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the POST parameter `title` is reflected back in a JSON response built with `json_encode()`. Because the response is ser...
CVE-2026-33910
- EPSS 0.03%
- Veröffentlicht 25.03.2026 22:41:02
- Zuletzt bearbeitet 26.03.2026 16:19:40
OpenEMR is a free and open source electronic health records and medical practice management application. Versions up to and including 8.0.0.2 contain a SQL injection vulnerability in the patient selection feature that can be exploited by authenticate...
CVE-2026-33909
- EPSS 0.02%
- Veröffentlicht 25.03.2026 22:35:29
- Zuletzt bearbeitet 26.03.2026 18:02:01
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, several variables in the MedEx recall/reminder processing code are concatenated directly into SQL queries without param...
CVE-2026-33348
- EPSS 0.07%
- Veröffentlicht 25.03.2026 22:30:37
- Zuletzt bearbeitet 26.03.2026 18:02:20
OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form are displayed on the encounter...
CVE-2026-32120
- EPSS 0.04%
- Veröffentlicht 25.03.2026 22:27:38
- Zuletzt bearbeitet 26.03.2026 18:03:30
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the fee sheet product save logic (`library/FeeSheet.class.p...
CVE-2026-29187
- EPSS 0.02%
- Veröffentlicht 25.03.2026 22:24:24
- Zuletzt bearbeitet 26.03.2026 16:19:59
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a Blind SQL Injection vulnerability exists in the Patient Search functionality (/interface/new/new_search_popup.php). T...