Open Emr Security Vulnerabilities (CVEs)

Track 42 security vulnerabilities affecting Open Emr products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

6 Critical
25 High
11 Medium
🔔 Get Alerts for Open Emr
CVE-2026-24898 10.0

OpenEMR versions before 8.0.0 contain an unauthenticated token disclosure vulnerability in the MedEx callback endpoint. Any unauthenticated visitor ca...

Mar 3, 2026
CVE-2026-27943 6.5

OpenEMR versions up to 8.0.0 contain an authorization bypass vulnerability in the eye exam module. Authenticated users can access or modify any patien...

Feb 26, 2026
CVE-2026-25746 8.8

OpenEMR versions before 8.0.0 contain a SQL injection vulnerability in the prescription listing functionality that allows authenticated attackers to e...

Feb 25, 2026
CVE-2026-25929 6.5

This vulnerability in OpenEMR allows authenticated users with document access control to bypass authorization checks and view other patients' photos b...

Feb 25, 2026
CVE-2026-25476 7.5

OpenEMR versions before 8.0.0 have a session expiration bypass vulnerability. Attackers can send a specific parameter (skip_timeout_reset=1) to preven...

Feb 25, 2026
CVE-2026-23627 8.8

An SQL injection vulnerability in OpenEMR's Immunization module allows authenticated users to execute arbitrary SQL queries by manipulating patient_id...

Feb 25, 2026
CVE-2026-24487 6.5

OpenEMR versions before 8.0.0 have an authorization bypass vulnerability in the FHIR CareTeam endpoint that allows patient-scoped tokens to access car...

Feb 25, 2026
CVE-2026-24890 8.1

OpenEMR patient portal users can forge provider signatures by exploiting an authorization bypass in the signature upload endpoint. This affects all Op...

Feb 25, 2026
CVE-2026-24908 9.9

OpenEMR versions before 8.0.0 contain an SQL injection vulnerability in the Patient REST API endpoint that allows authenticated users with API access ...

Feb 25, 2026
CVE-2026-25220 6.5

This vulnerability in OpenEMR allows any authenticated user to view all internal messages in the Message Center by accessing messages.php?show_all=yes...

Feb 25, 2026
CVE-2026-24849 9.9

CVE-2026-24849 is an arbitrary file read vulnerability in OpenEMR's EtherFaxActions.php. Any authenticated user, regardless of privilege level, can ex...

Feb 25, 2026
CVE-2026-25124 6.5

OpenEMR versions before 8.0.0 contain an access control vulnerability that allows low-privileged users (like receptionists) to export the entire messa...

Feb 25, 2026
CVE-2026-25131 8.8

OpenEMR versions before 8.0.0 contain a broken access control vulnerability that allows low-privilege users (like Receptionist role) to add and modify...

Feb 25, 2026
CVE-2026-24847 6.1

OpenEMR versions before 8.0.0 contain an open redirect vulnerability in the Eye Exam form module that allows authenticated users to be redirected to a...

Feb 25, 2026
CVE-2025-67752 8.1

OpenEMR versions before 7.0.4 have disabled SSL/TLS certificate verification by default in their HTTP client, making all HTTPS connections vulnerable ...

Feb 25, 2026
CVE-2025-69231 8.7

A stored cross-site scripting vulnerability in OpenEMR's GAD-7 anxiety assessment form allows authenticated clinicians to inject malicious JavaScript....

Feb 25, 2026
CVE-2025-67491 5.4

OpenEMR versions 5.0.0.5 through 7.0.3.4 have a stored cross-site scripting vulnerability in the billing interface's ub04 helper. Low-privileged users...

Feb 25, 2026
CVE-2025-54373 6.5

OpenEMR versions before 7.0.4 have an authorization bypass vulnerability where users without high-sensitivity privileges can view and modify clinical ...

Jan 28, 2026
CVE-2025-67645 8.8

OpenEMR versions before 7.0.4 have a broken access control vulnerability in the Profile Edit endpoint. Authenticated normal users can modify request p...

Jan 28, 2026
CVE-2021-47817 5.4

OpenEMR 5.0.2.1 contains a stored cross-site scripting vulnerability in user profile parameters that allows authenticated attackers to inject maliciou...

Jan 21, 2026
CVE-2013-10044 8.8

This CVE describes a critical vulnerability chain in OpenEMR where an authenticated attacker can perform SQL injection to steal administrator credenti...

Aug 1, 2025
CVE-2025-32794 7.6

OpenEMR versions before 7.0.3.4 have a stored XSS vulnerability where authenticated users with patient creation privileges can inject malicious JavaSc...

May 23, 2025
CVE-2025-43860 7.6

OpenEMR versions before 7.0.3.4 have a stored XSS vulnerability where authenticated users with patient editing privileges can inject malicious JavaScr...

May 23, 2025
CVE-2024-22611 9.8

CVE-2024-22611 is a critical SQL injection vulnerability in OpenEMR that allows attackers to execute arbitrary SQL commands through pharmacy-related c...

Apr 3, 2025
CVE-2025-31121 5.4

OpenEMR versions before 7.0.3.1 contain a cross-site scripting vulnerability in the Patient Image feature. Attackers can inject malicious scripts via ...

Apr 1, 2025
CVE-2025-31117 7.5

This Out-of-Band Server-Side Request Forgery (OOB SSRF) vulnerability in OpenEMR allows attackers to force the server to make unauthorized requests to...

Mar 31, 2025
CVE-2025-29789 7.5

OpenEMR versions before 7.3.0 contain a directory traversal vulnerability in the Load Code feature that allows attackers to read arbitrary files on th...

Mar 25, 2025
CVE-2024-0875 4.8

A stored cross-site scripting (XSS) vulnerability in OpenEMR 7.0.1 allows attackers to inject malicious scripts into the Secure Messaging feature's 'i...

Nov 15, 2024
CVE-2024-37734 9.8

CVE-2024-37734 is a privilege escalation vulnerability in OpenEMR 7.0.2 that allows remote attackers to gain elevated privileges by sending a speciall...

Jun 26, 2024
CVE-2023-2950 8.1

CVE-2023-2950 is an improper authorization vulnerability in OpenEMR that allows authenticated users to access administrative functions without proper ...

May 28, 2023
CVE-2023-2946 8.1

CVE-2023-2946 is an improper access control vulnerability in OpenEMR that allows unauthorized users to access sensitive patient data and administrativ...

May 27, 2023
CVE-2023-2943 8.8

CVE-2023-2943 is a code injection vulnerability in OpenEMR that allows attackers to execute arbitrary code on affected systems. This affects OpenEMR i...

May 27, 2023
CVE-2023-22973 8.8

This CVE describes a Local File Inclusion vulnerability in OpenEMR's interface/forms/LBF/new.php file that allows authenticated remote attackers to ex...

Feb 22, 2023
CVE-2022-2824 8.8

This vulnerability allows attackers to bypass authorization controls in OpenEMR by manipulating user-controlled keys, potentially accessing unauthoriz...

Aug 15, 2022
CVE-2022-2493 8.1

This vulnerability allows unauthorized data access by bypassing expected data manager component restrictions in OpenEMR. Attackers can access sensitiv...

Jul 22, 2022
CVE-2022-1459 8.3

This vulnerability allows non-privileged users to view patient disclosure information in OpenEMR, violating patient privacy and confidentiality. It af...

Apr 25, 2022
CVE-2020-13567 9.8

CVE-2020-13567 is a critical SQL injection vulnerability in phpGACL 3.3.7 that allows attackers to execute arbitrary SQL commands via specially crafte...

Apr 18, 2022
CVE-2022-25471 8.1

An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows authenticated attackers to access and modify unauthorized system area...

Mar 3, 2022
CVE-2021-25923 8.1

OpenEMR versions 5.0.0 to 6.0.0.1 have weak password requirements that don't enforce maximum password length. This allows attackers who know the first...

Jun 24, 2021
CVE-2021-32101 8.2

CVE-2021-32101 is an incorrect access control vulnerability in OpenEMR's Patient Portal that allows unauthenticated attackers to register accounts and...

May 7, 2021
CVE-2021-32104 8.8

This SQL injection vulnerability in OpenEMR's eye examination form interface allows authenticated users to execute arbitrary SQL commands on the datab...

May 7, 2021
CVE-2020-13566 8.8

This CVE describes a SQL injection vulnerability in phpGACL 3.3.7 that allows attackers to execute arbitrary SQL commands via specially crafted HTTP r...

Apr 13, 2021

Why Monitor Open Emr Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 42+ known vulnerabilities affecting Open Emr products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Open Emr packages in under 60 seconds. No agents required - completely agentless scanning that works across Open Emr deployments.

Free vulnerability database: Access detailed information about every Open Emr CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Open Emr CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Open Emr CVEs Free