Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

openemr — Vulnerabilities & Security Advisories 107

All 107 CVE vulnerabilities found in openemr, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the OpenEMR electronic health records software, categorized under general software weakness types. It collects a comprehensive range of security vulnerabilities, including cross-site scripting, injection flaws, path traversal, and improper access control issues affecting various versions of the OpenEMR application. The data spans from early 2009 through the present, ensuring coverage of both historical legacy flaws and recent critical security patches. By aggregating these records, this resource allows security professionals and system administrators to track vendor advisories and monitor the security posture of OpenEMR over time. Users can utilize this page to understand specific weakness classes as they apply to medical data management software, examining how different attack vectors have been exploited or mitigated in past releases. Furthermore, it serves as a lookup tool for reviewing the complete vulnerability history of the product, helping teams assess the impact of older, unpatched systems or verify the efficacy of recent security updates. This centralized view supports risk assessment, compliance auditing, and informed decision-making for healthcare organizations deploying or maintaining OpenEMR instances. The information is sourced from official vendor notifications and recognized security databases, providing a factual baseline for security analysis without editorial commentary or promotional content.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2026-40506 OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.php CWE-22 6.5 Medium2026-08-17
CVE-2026-67612 OpenEMR 8.2.0 Stored XSS via import_template.php Template Management CWE-79 4.8 Medium2026-08-03
CVE-2026-67611 OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration CWE-308 8.1 High2026-08-03
CVE-2026-67610 OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access CWE-306 8.1 High2026-08-03
CVE-2026-39932 OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection CWE-95 9.1 Critical2026-08-03
CVE-2026-39931 OpenEMR Authenticated SQL Injection via backup.php Import Feature CWE-434 7.2 High2026-08-03
CVE-2026-46518 OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics CWE-79 7.7 High2026-06-09
CVE-2023-54347 OpenEMR 7.0.1 Authentication Brute Force Mitigation Bypass CWE-307 7.5 High2026-05-05
CVE-2026-34056 OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data CWE-285 7.7 High2026-03-25
CVE-2026-34055 OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification CWE-639 8.1 High2026-03-25
CVE-2026-34053 OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler CWE-862 7.1 High2026-03-25
CVE-2026-34051 OpenEMR has Improper ACL On Import/Export Popup CWE-285 5.4 Medium2026-03-25
CVE-2026-33934 OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff Signatures CWE-639 4.3 Medium2026-03-25
CVE-2026-33933 Reflected XSS via Unescaped contextName Parameter in Custom Template Editor CWE-79 6.1 Medium2026-03-25
CVE-2026-33932 OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes CWE-79 7.6 High2026-03-25
CVE-2026-33931 OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access CWE-639 6.5 Medium2026-03-25
CVE-2026-33918 OpenEMR Missing Authorization on Claim File Download Endpoint CWE-862 7.6 High2026-03-25
CVE-2026-33917 OpenEMR has SQL Injection in CAMOS Form CWE-89 8.8 High2026-03-25
CVE-2026-33915 OpenEMR Missing ACL Checks on Insurance Company API Routes CWE-862 5.4 Medium2026-03-25
CVE-2026-33914 OpenEMR has SQL Injection in PostCalendar Category Delete CWE-89 7.2 High2026-03-25
CVE-2026-33913 OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files CWE-611 7.7 High2026-03-25
CVE-2026-33912 OpenEMR has reflected XSS in ajax_download.php via reportID parameter CWE-79 5.4 Medium2026-03-25
CVE-2026-33911 OpenEMR vulnerable to reflected XSS in graphs.php via title parameter CWE-79 5.4 Medium2026-03-25
CVE-2026-33910 OpenEMR has a SQL Injection Vulnerability in patient selection CWE-89 7.2 High2026-03-25
CVE-2026-33909 OpenEMR Vulnerable to SQL Injection via Unsanitized Variables in MedEx Recall/Reminder Processing CWE-89 5.9 Medium2026-03-25
CVE-2026-33348 OpenEMR has Stored XSS in patient encounter Eye Exam form $CHRONIC2 and $CHRONIC3 CWE-79 8.7 High2026-03-25
CVE-2026-32120 OpenEMR has IDOR in Fee Sheet Product Save CWE-639 6.5 Medium2026-03-25
CVE-2026-29187 OpenEMR Vulnerable to Authenticated Blind Boolean-Based SQL Injection in new_search_popup.php CWE-89 8.1 High2026-03-25
CVE-2026-33346 OpenEMR has stored XSS in portal_payment.php via Unescaped table_args CWE-79 8.7 High2026-03-19
CVE-2026-33305 OpenEMR has Authorization Bypass in FaxSMS AppDispatch Constructor CWE-696 5.4 Medium2026-03-19

All 107 known CVE vulnerabilities affecting openemr with full Chinese analysis, references, and POCs where available.