📦 Openmrs

by Openmrs

🔍 What is Openmrs?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-43094

CRITICAL CVSS 9.8 May 10, 2022

This SQL injection vulnerability in OpenMRS allows attackers to execute arbitrary SQL commands via GET request parameters on the patient.page endpoint. It affects OpenMRS Reference Application Standal...

CVE-2025-25928

HIGH CVSS 8.0 Mar 11, 2025

This CSRF vulnerability in OpenMRS 2.4.3 allows attackers to perform unauthorized administrative actions by tricking authenticated users into submitting malicious requests. Attackers can elevate low-p...

CVE-2022-23612

HIGH CVSS 7.5 Feb 22, 2022

CVE-2022-23612 is a path traversal vulnerability in OpenMRS that allows attackers to exfiltrate arbitrary files from the server. The vulnerability affects OpenMRS versions before 2.1.5, 2.2.1, 2.3.5, ...

CVE-2025-25929

MEDIUM CVSS 5.4 Mar 11, 2025

This reflected cross-site scripting (XSS) vulnerability in OpenMRS allows attackers to inject malicious JavaScript via the reportType parameter in the /legacyui/quickReportServlet component. When expl...

CVE-2025-25925

MEDIUM CVSS 4.8 Mar 11, 2025

A stored cross-site scripting (XSS) vulnerability in OpenMRS v2.4.3 Build 0ff0ed allows attackers to inject malicious scripts into the personName.middleName field. When administrators view patient for...