Openemr

Openemr

50 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.1%
  • Veröffentlicht 25.02.2026 01:53:15
  • Zuletzt bearbeitet 25.02.2026 16:01:07

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the server does not properly validate user permission. Unauthorized users can view the information of authorized users. V...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 25.02.2026 01:50:22
  • Zuletzt bearbeitet 25.02.2026 16:54:00

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the OpenEMR application is vulnerable to an access control flaw that allows low-privileged users, such as receptionists, ...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 25.02.2026 01:47:59
  • Zuletzt bearbeitet 25.02.2026 16:54:24

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Control vulnerability exists in OpenEMR’s edih_main.php endpoint, which allows any authenticated user—inc...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 25.02.2026 01:44:30
  • Zuletzt bearbeitet 25.02.2026 16:56:53

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument()` method in `EtherFaxActions.php` allows authenticated users to read arbitrary files from the serve...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 25.02.2026 01:34:35
  • Zuletzt bearbeitet 26.02.2026 15:33:56

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Eye Exam form module allows any authenticated user to be redirected to an arbitrary external URL. This can be exploit...

  • EPSS 0.11%
  • Veröffentlicht 25.02.2026 01:23:22
  • Zuletzt bearbeitet 26.02.2026 15:34:11

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the `xl()` translation function returns unescaped strings. While wrapper functions exist for escaping in different contex...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 25.02.2026 01:18:14
  • Zuletzt bearbeitet 25.02.2026 17:01:10

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a stored cross-site scripting vulnerability in the GAD-7 anxiety assessment form allows authenticated users with clinicia...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 25.02.2026 01:13:28
  • Zuletzt bearbeitet 25.02.2026 17:00:23

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, when a link is sent via Secure Messaging, clicking the link opens the website within the OpenEMR/Portal site. This behavi...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 25.02.2026 01:09:20
  • Zuletzt bearbeitet 25.02.2026 16:58:43

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default (`verify: f...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 25.02.2026 00:31:11
  • Zuletzt bearbeitet 25.02.2026 17:01:48

OpenEMR is a free and open source electronic health records and medical practice management application. Versions 5.0.0.5 through 7.0.3.4 have a stored cross-site scripting vulnerability in the ub04 helper of the billing interface. The variable `$dat...