📦 Openemr

by Open Emr

🔍 What is Openemr?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-24898

CRITICAL CVSS 10.0 Mar 3, 2026

OpenEMR versions before 8.0.0 contain an unauthenticated token disclosure vulnerability in the MedEx callback endpoint. Any unauthenticated visitor can obtain the practice's MedEx API tokens, leading ...

CVE-2026-24908

CRITICAL CVSS 9.9 Feb 25, 2026

OpenEMR versions before 8.0.0 contain an SQL injection vulnerability in the Patient REST API endpoint that allows authenticated users with API access to execute arbitrary SQL queries through the _sort...

CVE-2026-24849

CRITICAL CVSS 9.9 Feb 25, 2026

CVE-2026-24849 is an arbitrary file read vulnerability in OpenEMR's EtherFaxActions.php. Any authenticated user, regardless of privilege level, can exploit this to read sensitive files from the server...

CVE-2024-22611

CRITICAL CVSS 9.8 Apr 3, 2025

CVE-2024-22611 is a critical SQL injection vulnerability in OpenEMR that allows attackers to execute arbitrary SQL commands through pharmacy-related components. This affects OpenEMR 7.0.2 installation...

CVE-2024-37734

CRITICAL CVSS 9.8 Jun 26, 2024

CVE-2024-37734 is a privilege escalation vulnerability in OpenEMR 7.0.2 that allows remote attackers to gain elevated privileges by sending a specially crafted POST request with a manipulated noteid p...

CVE-2020-13567

CRITICAL CVSS 9.8 Apr 18, 2022

CVE-2020-13567 is a critical SQL injection vulnerability in phpGACL 3.3.7 that allows attackers to execute arbitrary SQL commands via specially crafted HTTP requests. This affects all systems running ...

CVE-2026-25746

HIGH CVSS 8.8 Feb 25, 2026

OpenEMR versions before 8.0.0 contain a SQL injection vulnerability in the prescription listing functionality that allows authenticated attackers to execute arbitrary SQL commands. This could lead to ...

CVE-2026-25476

HIGH CVSS 7.5 Feb 25, 2026

OpenEMR versions before 8.0.0 have a session expiration bypass vulnerability. Attackers can send a specific parameter (skip_timeout_reset=1) to prevent session timeout checks, allowing stolen session ...

CVE-2026-23627

HIGH CVSS 8.8 Feb 25, 2026

An SQL injection vulnerability in OpenEMR's Immunization module allows authenticated users to execute arbitrary SQL queries by manipulating patient_id parameters. This affects all OpenEMR installation...

CVE-2026-24890

HIGH CVSS 8.1 Feb 25, 2026

OpenEMR patient portal users can forge provider signatures by exploiting an authorization bypass in the signature upload endpoint. This affects all OpenEMR installations prior to version 8.0.0 where p...

CVE-2026-25131

HIGH CVSS 8.8 Feb 25, 2026

OpenEMR versions before 8.0.0 contain a broken access control vulnerability that allows low-privilege users (like Receptionist role) to add and modify medical procedure types without proper authorizat...

CVE-2025-67752

HIGH CVSS 8.1 Feb 25, 2026

OpenEMR versions before 7.0.4 have disabled SSL/TLS certificate verification by default in their HTTP client, making all HTTPS connections vulnerable to man-in-the-middle attacks. This exposes Protect...

CVE-2025-69231

HIGH CVSS 8.7 Feb 25, 2026

A stored cross-site scripting vulnerability in OpenEMR's GAD-7 anxiety assessment form allows authenticated clinicians to inject malicious JavaScript. When other users view the form, the script execut...

CVE-2025-67645

HIGH CVSS 8.8 Jan 28, 2026

OpenEMR versions before 7.0.4 have a broken access control vulnerability in the Profile Edit endpoint. Authenticated normal users can modify request parameters to reference other users' records, allow...

CVE-2013-10044

HIGH CVSS 8.8 Aug 1, 2025

This CVE describes a critical vulnerability chain in OpenEMR where an authenticated attacker can perform SQL injection to steal administrator credentials, escalate privileges, then exploit an unrestri...

CVE-2025-32794

HIGH CVSS 7.6 May 23, 2025

OpenEMR versions before 7.0.3.4 have a stored XSS vulnerability where authenticated users with patient creation privileges can inject malicious JavaScript into patient name fields. This code executes ...

CVE-2025-43860

HIGH CVSS 7.6 May 23, 2025

OpenEMR versions before 7.0.3.4 have a stored XSS vulnerability where authenticated users with patient editing privileges can inject malicious JavaScript into address fields. This allows attackers to ...

CVE-2025-31117

HIGH CVSS 7.5 Mar 31, 2025

This Out-of-Band Server-Side Request Forgery (OOB SSRF) vulnerability in OpenEMR allows attackers to force the server to make unauthorized requests to external or internal resources. Attackers can exp...

CVE-2025-29789

HIGH CVSS 7.5 Mar 25, 2025

OpenEMR versions before 7.3.0 contain a directory traversal vulnerability in the Load Code feature that allows attackers to read arbitrary files on the server. This affects all OpenEMR installations r...

CVE-2023-2950

HIGH CVSS 8.1 May 28, 2023

CVE-2023-2950 is an improper authorization vulnerability in OpenEMR that allows authenticated users to access administrative functions without proper permissions. This affects all OpenEMR installation...

CVE-2023-2946

HIGH CVSS 8.1 May 27, 2023

CVE-2023-2946 is an improper access control vulnerability in OpenEMR that allows unauthorized users to access sensitive patient data and administrative functions. This affects all OpenEMR installation...

CVE-2023-2943

HIGH CVSS 8.8 May 27, 2023

CVE-2023-2943 is a code injection vulnerability in OpenEMR that allows attackers to execute arbitrary code on affected systems. This affects OpenEMR installations prior to version 7.0.1. Healthcare or...

CVE-2023-22973

HIGH CVSS 8.8 Feb 22, 2023

This CVE describes a Local File Inclusion vulnerability in OpenEMR's interface/forms/LBF/new.php file that allows authenticated remote attackers to execute arbitrary code by manipulating the formname ...

CVE-2022-2824

HIGH CVSS 8.8 Aug 15, 2022

This vulnerability allows attackers to bypass authorization controls in OpenEMR by manipulating user-controlled keys, potentially accessing unauthorized data or functions. It affects all OpenEMR insta...

CVE-2022-2493

HIGH CVSS 8.1 Jul 22, 2022

This vulnerability allows unauthorized data access by bypassing expected data manager component restrictions in OpenEMR. Attackers can access sensitive patient data they shouldn't have permission to v...

CVE-2022-1459

HIGH CVSS 8.3 Apr 25, 2022

This vulnerability allows non-privileged users to view patient disclosure information in OpenEMR, violating patient privacy and confidentiality. It affects OpenEMR installations prior to version 6.1.0...

CVE-2022-25471

HIGH CVSS 8.1 Mar 3, 2022

An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows authenticated attackers to access and modify unauthorized system areas via crafted POST requests to the installer regis...

CVE-2021-25923

HIGH CVSS 8.1 Jun 24, 2021

OpenEMR versions 5.0.0 to 6.0.0.1 have weak password requirements that don't enforce maximum password length. This allows attackers who know the first 72 characters of a victim's password to perform a...

CVE-2021-32101

HIGH CVSS 8.2 May 7, 2021

CVE-2021-32101 is an incorrect access control vulnerability in OpenEMR's Patient Portal that allows unauthenticated attackers to register accounts and bypass permission checks. This enables attackers ...

CVE-2021-32104

HIGH CVSS 8.8 May 7, 2021

This SQL injection vulnerability in OpenEMR's eye examination form interface allows authenticated users to execute arbitrary SQL commands on the database. It affects OpenEMR installations running vers...

CVE-2020-13566

HIGH CVSS 8.8 Apr 13, 2021

This CVE describes a SQL injection vulnerability in phpGACL 3.3.7 that allows attackers to execute arbitrary SQL commands via specially crafted HTTP requests. The vulnerability exists in the admin/edi...

CVE-2026-27943

MEDIUM CVSS 6.5 Feb 26, 2026

OpenEMR versions up to 8.0.0 contain an authorization bypass vulnerability in the eye exam module. Authenticated users can access or modify any patient's eye exam data by manipulating form IDs, potent...

CVE-2026-25929

MEDIUM CVSS 6.5 Feb 25, 2026

This vulnerability in OpenEMR allows authenticated users with document access control to bypass authorization checks and view other patients' photos by manipulating patient or document IDs. It affects...

CVE-2026-24487

MEDIUM CVSS 6.5 Feb 25, 2026

OpenEMR versions before 8.0.0 have an authorization bypass vulnerability in the FHIR CareTeam endpoint that allows patient-scoped tokens to access care team data for all patients instead of just the a...

CVE-2026-25220

MEDIUM CVSS 6.5 Feb 25, 2026

This vulnerability in OpenEMR allows any authenticated user to view all internal messages in the Message Center by accessing messages.php?show_all=yes. The application fails to verify administrative p...

CVE-2026-24847

MEDIUM CVSS 6.1 Feb 25, 2026

OpenEMR versions before 8.0.0 contain an open redirect vulnerability in the Eye Exam form module that allows authenticated users to be redirected to arbitrary external URLs. This enables phishing atta...

CVE-2026-25124

MEDIUM CVSS 6.5 Feb 25, 2026

OpenEMR versions before 8.0.0 contain an access control vulnerability that allows low-privileged users (like receptionists) to export the entire message list containing sensitive patient and user data...

CVE-2025-67491

MEDIUM CVSS 5.4 Feb 25, 2026

OpenEMR versions 5.0.0.5 through 7.0.3.4 have a stored cross-site scripting vulnerability in the billing interface's ub04 helper. Low-privileged users can inject malicious JavaScript that executes whe...

CVE-2025-54373

MEDIUM CVSS 6.5 Jan 28, 2026

OpenEMR versions before 7.0.4 have an authorization bypass vulnerability where users without high-sensitivity privileges can view and modify clinical notes and care plans marked as high-sensitivity. T...

CVE-2021-47817

MEDIUM CVSS 5.4 Jan 21, 2026

OpenEMR 5.0.2.1 contains a stored cross-site scripting vulnerability in user profile parameters that allows authenticated attackers to inject malicious JavaScript. This can lead to remote command exec...

CVE-2025-31121

MEDIUM CVSS 5.4 Apr 1, 2025

OpenEMR versions before 7.0.3.1 contain a cross-site scripting vulnerability in the Patient Image feature. Attackers can inject malicious scripts via EXIF title metadata in uploaded images, which then...

CVE-2024-0875

MEDIUM CVSS 4.8 Nov 15, 2024

A stored cross-site scripting (XSS) vulnerability in OpenEMR 7.0.1 allows attackers to inject malicious scripts into the Secure Messaging feature's 'inputBody' field. When other users view these messa...