Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenEMR — Vulnerabilities & Security Advisories 131

Browse all 131 CVE security advisories affecting OpenEMR. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenEMR is an open-source electronic health record and medical practice management application designed to facilitate patient data management and clinical workflows. Historically, its codebase has exhibited significant security flaws, with over 120 Common Vulnerabilities and Exposures (CVEs) recorded. These vulnerabilities predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and improper access controls within the PHP-based architecture. Notable incidents include critical flaws allowing unauthenticated attackers to execute arbitrary commands or bypass authentication mechanisms, exposing sensitive patient information. The high volume of historical CVEs reflects challenges in maintaining rigorous security standards across a large, community-driven codebase. While recent updates have addressed many issues, the application’s complexity and extensive feature set continue to present attack surfaces that require diligent patching and configuration hardening to mitigate risks associated with data breaches and unauthorized system access.

Found 94 results / 131 Clear Filters
Top products by OpenEMR: OpenEMR openemr/openemr
CVE ID Title CVSS Severity Published
CVE-2025-30149 OpenEMR Reflected XSS in AJAX Script — openemr CWE-79 6.4 Medium 2025-03-31
CVE-2025-29772 OpenEMR allows Reflected XSS in CAMOS new.php — openemr CWE-79 6.1 - 2025-03-31
CVE-2025-29789 OpenEMR Has Directory Traversal in Load Code feature — openemr CWE-23 6.5AI Medium AI 2025-03-25
CVE-2020-13567 phpGACL SQL注入漏洞 — OpenEMR CWE-89 9.8 - 2022-04-18

This page lists every published CVE security advisory associated with OpenEMR. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.