Vulnerabilities in OpenEMR

131 results
Vexday analysis

OpenEMR possui apenas 1 vulnerabilidade registrada na base, classificada como injeção SQL (CWE-89), sem evidências de ataque ativo ou severidade crítica. O risco atual é baixo, mas a natureza da fraqueza—injeção SQL—demanda atenção contínua em atualizações de segurança, especialmente em ambientes clínicos que armazenam dados sensíveis.

CVE-2026-33910HIGHOpenEMR has a SQL Injection Vulnerability in patient selectionEPSS 0.4%CVE-2026-33914HIGHOpenEMR has SQL Injection in PostCalendar Category DeleteEPSS 0.4%CVE-2026-34053HIGHOpenEMR Missing Authorization in Procedure Order AJAX Deletion HandlerEPSS 0.4%CVE-2026-24488MEDIUMOpenEMR Vulnerable to Arbitrary File Exfiltration via Fax EndpointEPSS 0.4%CVE-2025-54373HIGHOpenEMR may expose Contents of Clinical Notes and Care Planto users who do not have Sensitivities=high privilegeEPSS 0.4%CVE-2024-0875HIGHStored XSS in openemr/openemrEPSS 0.4%CVE-2025-67645HIGHOpenEMR Vulnerable to Broken Access Control in Profile Edit EndpointEPSS 0.4%CVE-2026-33931MEDIUMOpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record AccessEPSS 0.4%CVE-2026-76614MEDIUMOpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive RestoreEPSS 0.3%CVE-2026-33909MEDIUMOpenEMR Vulnerable to SQL Injection via Unsanitized Variables in MedEx Recall/Reminder ProcessingEPSS 0.3%CVE-2026-32127HIGHSQL Injection Vulnerability in ajax graphs library (OpenEMR)EPSS 0.3%CVE-2026-67610HIGHOpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR AccessEPSS 0.3%CVE-2026-25131HIGHOpenEMR has Broken Access Control in Procedures ConfigurationEPSS 0.3%CVE-2026-33346HIGHOpenEMR has stored XSS in portal_payment.php via Unescaped table_argsEPSS 0.3%CVE-2025-30149MEDIUMOpenEMR Reflected XSS in AJAX ScriptEPSS 0.3%CVE-2026-33302HIGHOpenEMR: zhAclCheck Ignores Explicit ACL DeniesEPSS 0.3%CVE-2026-33304MEDIUMOpenEMR has Authorization Bypass in Dated Reminders LogEPSS 0.3%CVE-2026-25476HIGHOpenEMR has Session Timeout Bypass via skip_timeout_resetEPSS 0.3%CVE-2026-40507MEDIUMOpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient PortalEPSS 0.3%CVE-2026-33348HIGHOpenEMR has Stored XSS in patient encounter Eye Exam form $CHRONIC2 and $CHRONIC3EPSS 0.3%