Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

openemr — Vulnerabilities & Security Advisories 107

All 107 CVE vulnerabilities found in openemr, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the OpenEMR electronic health records software, categorized under general software weakness types. It collects a comprehensive range of security vulnerabilities, including cross-site scripting, injection flaws, path traversal, and improper access control issues affecting various versions of the OpenEMR application. The data spans from early 2009 through the present, ensuring coverage of both historical legacy flaws and recent critical security patches. By aggregating these records, this resource allows security professionals and system administrators to track vendor advisories and monitor the security posture of OpenEMR over time. Users can utilize this page to understand specific weakness classes as they apply to medical data management software, examining how different attack vectors have been exploited or mitigated in past releases. Furthermore, it serves as a lookup tool for reviewing the complete vulnerability history of the product, helping teams assess the impact of older, unpatched systems or verify the efficacy of recent security updates. This centralized view supports risk assessment, compliance auditing, and informed decision-making for healthcare organizations deploying or maintaining OpenEMR instances. The information is sourced from official vendor notifications and recognized security databases, providing a factual baseline for security analysis without editorial commentary or promotional content.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2026-33304 OpenEMR has Authorization Bypass in Dated Reminders Log CWE-639 6.5 Medium2026-03-19
CVE-2026-33303 OpenEMR Vulnerable to Stored XSS via Unescaped portal_login_username in Credential Print View CWE-79 5.4 Medium2026-03-19
CVE-2026-33302 OpenEMR: zhAclCheck Ignores Explicit ACL Denies CWE-863 7.6 -2026-03-19
CVE-2026-33321 OpenEMR has Out-of-Band Server-Side Request Forgery (OOB SSRF) CWE-918 7.6 -2026-03-19
CVE-2026-33301 OpenEMR has arbitrary image file read via PDF generator CWE-116 3.5 -2026-03-19
CVE-2026-33299 OpenEMR has Stored XSS in patient encounter Eye Exam form answers CWE-79 5.4 -2026-03-19
CVE-2026-32119 OpenEMR has Stored DOM XSS via SearchHighlight text-node reconstruction on Custom Report page CWE-79 4.4 Medium2026-03-19
CVE-2026-32238 OpenEMR has Remote Code Execution in backup functionality CWE-78 9.1 Critical2026-03-19
CVE-2026-25928 OpenEMR Vulnerable to Path Traversal When Zipping DICOM Folders CWE-22 6.5 Medium2026-03-19
CVE-2026-25744 OpenEMR: POST /api/.../vital Accepts Attacker-Supplied id and Overwrites Arbitrary Vitals CWE-639 6.5 Medium2026-03-19
CVE-2026-25745 OpenEMR's Message Update Ignores Patient id CWE-639 6.5 Medium2026-03-18
CVE-2026-32127 SQL Injection Vulnerability in ajax graphs library (OpenEMR) CWE-89 8.8 High2026-03-11
CVE-2026-32126 OpenEMR: Inverted ACL Condition in CDR ControllerRouter Allows Any Authenticated User to Modify/Delete Clinical Rules and Plans CWE-862 7.1 High2026-03-11
CVE-2026-32125 OpenEMR: Stored XSS in Track Anything Graphs via Unescaped Dygraph Titles/Labels CWE-79 5.4 Medium2026-03-11
CVE-2026-32124 OpenEMR: Dynamic Code Picker Renders Unescaped Descriptions (Stored XSS) CWE-79 5.4 Medium2026-03-11
CVE-2026-32123 OpenEMR: Therapy Group Sensitivity ACL No Longer Enforced CWE-863 7.7 High2026-03-11
CVE-2026-32122 OpenEMR: Missing Authorization on Claim File Tracker UI and AJAX Endpoint (V2) CWE-862 4.3 Medium2026-03-11
CVE-2026-32121 OpenEMR: Stored DOM XSS via `.html()` in Portal Signer Modal CWE-79 7.7 High2026-03-11
CVE-2026-32118 OpenEMR has Stored XSS in Graphical Pain Map legend via unescaped annotation text CWE-79 5.4 Medium2026-03-11
CVE-2026-24898 OpenEMR has an Unauthenticated MedEx Token Disclosure CWE-287 10.0 Critical2026-03-03
CVE-2026-25146 OpenEMR's payments gateway_api_key secret rendered into client JS code CWE-200 9.6 Critical2026-03-03
CVE-2026-24848 OpenEMR Arbitrary File Write leading to Remote Code Execution CWE-22 8.8AIHighAI2026-03-03
CVE-2026-25147 OpenEMR's Portal Payment Endpoint Trusts User-Controlled pid CWE-639 7.1 High2026-02-27
CVE-2026-24488 OpenEMR Vulnerable to Arbitrary File Exfiltration via Fax Endpoint CWE-22 6.5 Medium2026-02-27
CVE-2026-27943 OpenEMR's Eye Exam View Trusts form_id Without Verifying Patient/Encounter Ownership CWE-639 6.5 Medium2026-02-26
CVE-2026-25930 OpenEMR's Printable LBF Endpoint Leaks Arbitrary Patient Forms CWE-639 6.5 Medium2026-02-25
CVE-2026-25929 OpenEMR Patient Picture Context Allows Arbitrary Patient Photo Retrieval CWE-639 6.5 Medium2026-02-25
CVE-2026-25927 OpenEMR Missing Authorization Checks in DICOM Viewer State API CWE-639 7.1 High2026-02-25
CVE-2026-25746 OpenEMR has SQL Injection Vulnerability CWE-89 8.8 High2026-02-25
CVE-2026-25743 OpenEMR has Stored XSS in Questionnaire answers CWE-79 5.4AIMediumAI2026-02-25

All 107 known CVE vulnerabilities affecting openemr with full Chinese analysis, references, and POCs where available.