All 107 CVE vulnerabilities found in openemr, with AI-generated Chinese analysis, references, and POCs.
This page is a vulnerability aggregation resource for the OpenEMR electronic health records software, categorized under general software weakness types. It collects a comprehensive range of security vulnerabilities, including cross-site scripting, injection flaws, path traversal, and improper access control issues affecting various versions of the OpenEMR application. The data spans from early 2009 through the present, ensuring coverage of both historical legacy flaws and recent critical security patches. By aggregating these records, this resource allows security professionals and system administrators to track vendor advisories and monitor the security posture of OpenEMR over time. Users can utilize this page to understand specific weakness classes as they apply to medical data management software, examining how different attack vectors have been exploited or mitigated in past releases. Furthermore, it serves as a lookup tool for reviewing the complete vulnerability history of the product, helping teams assess the impact of older, unpatched systems or verify the efficacy of recent security updates. This centralized view supports risk assessment, compliance auditing, and informed decision-making for healthcare organizations deploying or maintaining OpenEMR instances. The information is sourced from official vendor notifications and recognized security databases, providing a factual baseline for security analysis without editorial commentary or promotional content.
Vendor: n/a
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-29772 | OpenEMR allows Reflected XSS in CAMOS new.php CWE-79 | 6.1 | - | 2025-03-31 |
| CVE-2025-29789 | OpenEMR Has Directory Traversal in Load Code feature CWE-23 | 6.5AI | MediumAI | 2025-03-25 |
| CVE-2020-13567 | phpGACL SQL注入漏洞 CWE-89 | 9.8 | - | 2022-04-18 |
| CVE-2021-25923 | OpenEMR 安全漏洞 | 8.1 | - | 2021-06-24 |
| CVE-2021-25922 | OpenEMR 跨站脚本漏洞 | 6.1 | - | 2021-03-22 |
| CVE-2021-25917 | OpenEMR 跨站脚本漏洞 | 4.8 | - | 2021-03-22 |
| CVE-2021-25918 | OpenEMR 跨站脚本漏洞 | 4.8 | - | 2021-03-22 |
| CVE-2021-25920 | OpenEMR 安全漏洞 | 6.5 | - | 2021-03-22 |
| CVE-2021-25921 | OpenEMR 跨站脚本漏洞 | 5.4 | - | 2021-03-22 |
| CVE-2021-25919 | OpenEMR 跨站脚本漏洞 | 4.8 | - | 2021-03-22 |
| CVE-2020-13569 | OpenEMR 跨站请求伪造漏洞 CWE-352 | 8.8 | - | 2021-01-28 |
| CVE-2019-3968 | OpenEMR 命令注入漏洞 | 8.8 | - | 2019-08-20 |
| CVE-2019-3967 | OpenEMR 路径遍历漏洞 | 6.5 | - | 2019-08-20 |
| CVE-2019-3966 | OpenEMR 跨站脚本漏洞 | 6.1 | - | 2019-08-20 |
| CVE-2019-3965 | OpenEMR 跨站脚本漏洞 | 6.1 | - | 2019-08-20 |
| CVE-2019-3964 | OpenEMR 跨站脚本漏洞 | 6.1 | - | 2019-08-20 |
| CVE-2019-3963 | OpenEMR 跨站脚本漏洞 | 6.1 | - | 2019-08-20 |
All 107 known CVE vulnerabilities affecting openemr with full Chinese analysis, references, and POCs where available.