Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenEMR — Vulnerabilities & Security Advisories 111

All 111 CVE vulnerabilities found in OpenEMR, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the OpenEMR electronic health records software, categorized under general software weakness types. It collects a comprehensive range of security vulnerabilities, including cross-site scripting, injection flaws, path traversal, and improper access control issues affecting various versions of the OpenEMR application. The data spans from early 2009 through the present, ensuring coverage of both historical legacy flaws and recent critical security patches. By aggregating these records, this resource allows security professionals and system administrators to track vendor advisories and monitor the security posture of OpenEMR over time. Users can utilize this page to understand specific weakness classes as they apply to medical data management software, examining how different attack vectors have been exploited or mitigated in past releases. Furthermore, it serves as a lookup tool for reviewing the complete vulnerability history of the product, helping teams assess the impact of older, unpatched systems or verify the efficacy of recent security updates. This centralized view supports risk assessment, compliance auditing, and informed decision-making for healthcare organizations deploying or maintaining OpenEMR instances. The information is sourced from official vendor notifications and recognized security databases, providing a factual baseline for security analysis without editorial commentary or promotional content.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-76614 OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore CWE-22 4.3 Medium 2026-08-19
CVE-2026-40509 OpenEMR < 8.3.0 CSRF via DICOM Viewer web_path Parameter CWE-352 4.3 Medium 2026-08-19
CVE-2026-40508 OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler CWE-79 5.4 Medium 2026-08-19
CVE-2026-40507 OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portal CWE-79 6.1 Medium 2026-08-19
CVE-2026-40506 OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.php CWE-22 6.5 Medium 2026-08-17
CVE-2026-67612 OpenEMR 8.2.0 Stored XSS via import_template.php Template Management CWE-79 4.8 Medium 2026-08-03
CVE-2026-67611 OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration CWE-308 8.1 High 2026-08-03
CVE-2026-67610 OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access CWE-306 8.1 High 2026-08-03
CVE-2026-39932 OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection CWE-95 9.1 Critical 2026-08-03
CVE-2026-39931 OpenEMR Authenticated SQL Injection via backup.php Import Feature CWE-434 7.2 High 2026-08-03
CVE-2026-46518 OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics CWE-79 7.7 High 2026-06-09
CVE-2023-54347 OpenEMR 7.0.1 Authentication Brute Force Mitigation Bypass CWE-307 7.5 High 2026-05-05
CVE-2026-34056 OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data CWE-285 7.7 High 2026-03-25
CVE-2026-34055 OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification CWE-639 8.1 High 2026-03-25
CVE-2026-34053 OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler CWE-862 7.1 High 2026-03-25
CVE-2026-34051 OpenEMR has Improper ACL On Import/Export Popup CWE-285 5.4 Medium 2026-03-25
CVE-2026-33934 OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff Signatures CWE-639 4.3 Medium 2026-03-25
CVE-2026-33933 Reflected XSS via Unescaped contextName Parameter in Custom Template Editor CWE-79 6.1 Medium 2026-03-25
CVE-2026-33932 OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes CWE-79 7.6 High 2026-03-25
CVE-2026-33931 OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access CWE-639 6.5 Medium 2026-03-25
CVE-2026-33918 OpenEMR Missing Authorization on Claim File Download Endpoint CWE-862 7.6 High 2026-03-25
CVE-2026-33917 OpenEMR has SQL Injection in CAMOS Form CWE-89 8.8 High 2026-03-25
CVE-2026-33915 OpenEMR Missing ACL Checks on Insurance Company API Routes CWE-862 5.4 Medium 2026-03-25
CVE-2026-33914 OpenEMR has SQL Injection in PostCalendar Category Delete CWE-89 7.2 High 2026-03-25
CVE-2026-33913 OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files CWE-611 7.7 High 2026-03-25
CVE-2026-33912 OpenEMR has reflected XSS in ajax_download.php via reportID parameter CWE-79 5.4 Medium 2026-03-25
CVE-2026-33911 OpenEMR vulnerable to reflected XSS in graphs.php via title parameter CWE-79 5.4 Medium 2026-03-25
CVE-2026-33910 OpenEMR has a SQL Injection Vulnerability in patient selection CWE-89 7.2 High 2026-03-25
CVE-2026-33909 OpenEMR Vulnerable to SQL Injection via Unsanitized Variables in MedEx Recall/Reminder Processing CWE-89 5.9 Medium 2026-03-25
CVE-2026-33348 OpenEMR has Stored XSS in patient encounter Eye Exam form $CHRONIC2 and $CHRONIC3 CWE-79 8.7 High 2026-03-25

All 111 known CVE vulnerabilities affecting OpenEMR with full Chinese analysis, references, and POCs where available.