OpenEMR是OpenEMR社区的一套开源的医疗管理系统。该系统可用于医疗实践管理、电子医疗记录、处方书写和医疗帐单申请。 OpenEMR 5.0.0.5版本至7.0.3.4版本存在安全漏洞,该漏洞源于计费界面ub04助手存在存储型跨站脚本,变量$data在单引号内的点击事件处理程序中传递且清理不当,可能导致低权限用户嵌入恶意JS有效载荷并执行存储型跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-24908 | 10.0 CRITICAL | OpenEMR has SQL Injection in Patient API Sort Parameter |
| CVE-2026-24849 | 10.0 CRITICAL | OpenEMR Arbitrary File Read Vulnerability |
| CVE-2026-25746 | 8.8 HIGH | OpenEMR has SQL Injection Vulnerability |
| CVE-2026-25131 | 8.8 HIGH | OpenEMR has Broken Access Control in Procedures Configuration |
| CVE-2025-69231 | 8.7 HIGH | OpenEMR has a Stored XSS in GAD-7 Form that Enables Session Hijacking and Privilege Escala |
| CVE-2026-25164 | 8.1 HIGH | OpenEMR's Document and Insurance REST Endpoints Skip ACL |
| CVE-2026-24890 | 8.1 HIGH | OpenEMR Portal Users Can Forge Provider Signatures |
| CVE-2025-67752 | 8.1 HIGH | OpenEMR Has Disabled SSL Certificate Verification in HTTP Client |
| CVE-2026-25476 | 7.5 HIGH | OpenEMR has Session Timeout Bypass via skip_timeout_reset |
| CVE-2026-25927 | 7.1 HIGH | OpenEMR Missing Authorization Checks in DICOM Viewer State API |
| CVE-2026-25124 | 6.5 MEDIUM | OpenEMR has Broken Access Control in Report/Clients/Message List CSV Export |
| CVE-2026-24896 | 6.5 MEDIUM | OpenEMR has Broken Access Control that allows unauthorized access to EDI Logs |
| CVE-2026-25929 | 6.5 MEDIUM | OpenEMR Patient Picture Context Allows Arbitrary Patient Photo Retrieval |
| CVE-2026-25930 | 6.5 MEDIUM | OpenEMR's Printable LBF Endpoint Leaks Arbitrary Patient Forms |
| CVE-2026-24847 | 6.1 MEDIUM | OpenEMR has Open Redirect in Eye Exam Form |
| CVE-2026-25135 | 4.5 MEDIUM | OpenEMR's location resource for Group.$export operation returns entire patient/user popula |
| CVE-2026-25743 | OpenEMR has Stored XSS in Questionnaire answers | |
| CVE-2025-68277 | OpenEMR allows links sent via Secure Messaging to be opened in OpenEMR and Portal | |
| CVE-2026-25220 | OpenEMR Messages "Show All" Not Restricted to Admins | |
| CVE-2026-23627 | OpenEMR has SQL Injection in Immunization Search/Report |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet