Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

openemr — Vulnerabilities & Security Advisories 107

All 107 CVE vulnerabilities found in openemr, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the OpenEMR electronic health records software, categorized under general software weakness types. It collects a comprehensive range of security vulnerabilities, including cross-site scripting, injection flaws, path traversal, and improper access control issues affecting various versions of the OpenEMR application. The data spans from early 2009 through the present, ensuring coverage of both historical legacy flaws and recent critical security patches. By aggregating these records, this resource allows security professionals and system administrators to track vendor advisories and monitor the security posture of OpenEMR over time. Users can utilize this page to understand specific weakness classes as they apply to medical data management software, examining how different attack vectors have been exploited or mitigated in past releases. Furthermore, it serves as a lookup tool for reviewing the complete vulnerability history of the product, helping teams assess the impact of older, unpatched systems or verify the efficacy of recent security updates. This centralized view supports risk assessment, compliance auditing, and informed decision-making for healthcare organizations deploying or maintaining OpenEMR instances. The information is sourced from official vendor notifications and recognized security databases, providing a factual baseline for security analysis without editorial commentary or promotional content.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2026-25476 OpenEMR has Session Timeout Bypass via skip_timeout_reset CWE-613 7.5 High2026-02-25
CVE-2026-25220 OpenEMR Messages "Show All" Not Restricted to Admins CWE-639 4.3AIMediumAI2026-02-25
CVE-2026-25164 OpenEMR's Document and Insurance REST Endpoints Skip ACL CWE-862 8.1 High2026-02-25
CVE-2026-24908 OpenEMR has SQL Injection in Patient API Sort Parameter CWE-89 10.0 Critical2026-02-25
CVE-2026-24890 OpenEMR Portal Users Can Forge Provider Signatures CWE-285 8.1 High2026-02-25
CVE-2026-24487 OpenEMR has FHIR Patient Compartment Bypass in CareTeam Resource CWE-200 7.5AIHighAI2026-02-25
CVE-2026-23627 OpenEMR has SQL Injection in Immunization Search/Report CWE-89 8.8AIHighAI2026-02-25
CVE-2026-25135 OpenEMR's location resource for Group.$export operation returns entire patient/user population contact information CWE-200 4.5 Medium2026-02-25
CVE-2026-25131 OpenEMR has Broken Access Control in Procedures Configuration CWE-862 8.8 High2026-02-25
CVE-2026-25127 OpenEMR has Broken Access Control on Care Coordination Module CWE-863 3.5 -2026-02-25
CVE-2026-25124 OpenEMR has Broken Access Control in Report/Clients/Message List CSV Export CWE-862 6.5 Medium2026-02-25
CVE-2026-24896 OpenEMR has Broken Access Control that allows unauthorized access to EDI Logs CWE-284 6.5 Medium2026-02-25
CVE-2026-24849 OpenEMR Arbitrary File Read Vulnerability CWE-22 10.0 Critical2026-02-25
CVE-2026-24847 OpenEMR has Open Redirect in Eye Exam Form CWE-601 6.1 Medium2026-02-25
CVE-2026-21443 OpenEMR allows inconsistent escaping of translation function output CWE-116 6.1 -2026-02-25
CVE-2025-69231 OpenEMR has a Stored XSS in GAD-7 Form that Enables Session Hijacking and Privilege Escalation CWE-79 8.7 High2026-02-25
CVE-2025-68277 OpenEMR allows links sent via Secure Messaging to be opened in OpenEMR and Portal CWE-451 6.1 -2026-02-25
CVE-2025-67752 OpenEMR Has Disabled SSL Certificate Verification in HTTP Client CWE-295 8.1 High2026-02-25
CVE-2025-67491 OpenEMR has Stored XSS in ub04 helper CWE-79 5.4 -2026-02-25
CVE-2025-67645 OpenEMR Vulnerable to Broken Access Control in Profile Edit Endpoint CWE-284 8.8 High2026-01-27
CVE-2025-54373 OpenEMR may expose Contents of Clinical Notes and Care Planto users who do not have Sensitivities=high privilege CWE-200 5.4AIMediumAI2026-01-27
CVE-2021-47817 OpenEMR 5.0.2.1 - Remote Code Execution CWE-79 5.4 Medium2026-01-21
CVE-2013-10044 OpenEMR ≤ 4.1.1 SQL Injection Privilege Escalation and RCE CWE-89 9.9 -2025-08-01
CVE-2025-43860 OpemEMR Vulnerable to Stored XSS Attack in the Additional Address Section of Patient Demographics CWE-79 7.6 High2025-05-23
CVE-2025-32967 OpenEMR doesn't log password administration properly CWE-778 5.4 Medium2025-05-23
CVE-2025-32794 OpenEMR Stored XSS via Patient Name Field in Procedure Orders CWE-79 7.6 High2025-05-23
CVE-2025-31121 OpenEMR allows XSS in Patient Image feature CWE-79 5.4AIMediumAI2025-04-01
CVE-2025-31117 OpenEMR Out-of-Band Server-Side Request Forgery (OOB SSRF) Vulnerability CWE-918 7.5 -2025-03-31
CVE-2025-30161 OpenEMR Stored XSS in OpenEMR Bronchitis Form CWE-80 5.4 -2025-03-31
CVE-2025-30149 OpenEMR Reflected XSS in AJAX Script CWE-79 6.4 Medium2025-03-31

All 107 known CVE vulnerabilities affecting openemr with full Chinese analysis, references, and POCs where available.