Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenEMR — Vulnerabilities & Security Advisories 131

Browse all 131 CVE security advisories affecting OpenEMR. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenEMR is an open-source electronic health record and medical practice management application designed to facilitate patient data management and clinical workflows. Historically, its codebase has exhibited significant security flaws, with over 120 Common Vulnerabilities and Exposures (CVEs) recorded. These vulnerabilities predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and improper access controls within the PHP-based architecture. Notable incidents include critical flaws allowing unauthenticated attackers to execute arbitrary commands or bypass authentication mechanisms, exposing sensitive patient information. The high volume of historical CVEs reflects challenges in maintaining rigorous security standards across a large, community-driven codebase. While recent updates have addressed many issues, the application’s complexity and extensive feature set continue to present attack surfaces that require diligent patching and configuration hardening to mitigate risks associated with data breaches and unauthorized system access.

Top products by OpenEMR: OpenEMR openemr/openemr
CVE ID Title CVSS Severity Published
CVE-2026-76614 OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore — openemr CWE-22 4.3 Medium 2026-08-19
CVE-2026-40509 OpenEMR < 8.3.0 CSRF via DICOM Viewer web_path Parameter — openemr CWE-352 4.3 Medium 2026-08-19
CVE-2026-40508 OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler — openemr CWE-79 5.4 Medium 2026-08-19
CVE-2026-40507 OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portal — openemr CWE-79 6.1 Medium 2026-08-19
CVE-2026-40506 OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.php — openemr CWE-22 6.5 Medium 2026-08-17
CVE-2026-67612 OpenEMR 8.2.0 Stored XSS via import_template.php Template Management — openemr CWE-79 4.8 Medium 2026-08-03
CVE-2026-67611 OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration — openemr CWE-308 8.1 High 2026-08-03
CVE-2026-67610 OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access — openemr CWE-306 8.1 High 2026-08-03
CVE-2026-39932 OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection — openemr CWE-95 9.1 Critical 2026-08-03
CVE-2026-39931 OpenEMR Authenticated SQL Injection via backup.php Import Feature — openemr CWE-434 7.2 High 2026-08-03
CVE-2026-46518 OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics — openemr CWE-79 7.7 High 2026-06-09
CVE-2026-34056 OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data — openemr CWE-285 7.7 High 2026-03-25
CVE-2026-34055 OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification — openemr CWE-639 8.1 High 2026-03-25
CVE-2026-34053 OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler — openemr CWE-862 7.1 High 2026-03-25
CVE-2026-34051 OpenEMR has Improper ACL On Import/Export Popup — openemr CWE-285 5.4 Medium 2026-03-25
CVE-2026-33934 OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff Signatures — openemr CWE-639 4.3 Medium 2026-03-25
CVE-2026-33933 Reflected XSS via Unescaped contextName Parameter in Custom Template Editor — openemr CWE-79 6.1 Medium 2026-03-25
CVE-2026-33932 OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes — openemr CWE-79 7.6 High 2026-03-25
CVE-2026-33931 OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access — openemr CWE-639 6.5 Medium 2026-03-25
CVE-2026-33918 OpenEMR Missing Authorization on Claim File Download Endpoint — openemr CWE-862 7.6 High 2026-03-25
CVE-2026-33917 OpenEMR has SQL Injection in CAMOS Form — openemr CWE-89 8.8 High 2026-03-25
CVE-2026-33915 OpenEMR Missing ACL Checks on Insurance Company API Routes — openemr CWE-862 5.4 Medium 2026-03-25
CVE-2026-33914 OpenEMR has SQL Injection in PostCalendar Category Delete — openemr CWE-89 7.2 High 2026-03-25
CVE-2026-33913 OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files — openemr CWE-611 7.7 High 2026-03-25
CVE-2026-33912 OpenEMR has reflected XSS in ajax_download.php via reportID parameter — openemr CWE-79 5.4 Medium 2026-03-25
CVE-2026-33911 OpenEMR vulnerable to reflected XSS in graphs.php via title parameter — openemr CWE-79 5.4 Medium 2026-03-25
CVE-2026-33910 OpenEMR has a SQL Injection Vulnerability in patient selection — openemr CWE-89 7.2 High 2026-03-25
CVE-2026-33909 OpenEMR Vulnerable to SQL Injection via Unsanitized Variables in MedEx Recall/Reminder Processing — openemr CWE-89 5.9 Medium 2026-03-25
CVE-2026-33348 OpenEMR has Stored XSS in patient encounter Eye Exam form $CHRONIC2 and $CHRONIC3 — openemr CWE-79 8.7 High 2026-03-25
CVE-2026-32120 OpenEMR has IDOR in Fee Sheet Product Save — openemr CWE-639 6.5 Medium 2026-03-25

This page lists every published CVE security advisory associated with OpenEMR. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.