Vulnerabilities in OpenEMR
131 resultsVexday analysis
OpenEMR possui apenas 1 vulnerabilidade registrada na base, classificada como injeção SQL (CWE-89), sem evidências de ataque ativo ou severidade crítica. O risco atual é baixo, mas a natureza da fraqueza—injeção SQL—demanda atenção contínua em atualizações de segurança, especialmente em ambientes clínicos que armazenam dados sensíveis.
CVE-2026-33932HIGHOpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml AttributesEPSS 0.2%CVE-2026-24847MEDIUMOpenEMR has Open Redirect in Eye Exam FormEPSS 0.2%CVE-2026-33299HIGHOpenEMR has Stored XSS in patient encounter Eye Exam form answersEPSS 0.2%CVE-2026-25743HIGHOpenEMR has Stored XSS in Questionnaire answersEPSS 0.2%CVE-2026-32125MEDIUMOpenEMR: Stored XSS in Track Anything Graphs via Unescaped Dygraph Titles/LabelsEPSS 0.2%CVE-2026-32124MEDIUMOpenEMR: Dynamic Code Picker Renders Unescaped Descriptions (Stored XSS)EPSS 0.2%CVE-2025-68277HIGHOpenEMR allows links sent via Secure Messaging to be opened in OpenEMR and PortalEPSS 0.2%CVE-2026-32119MEDIUMOpenEMR has Stored DOM XSS via SearchHighlight text-node reconstruction on Custom Report pageEPSS 0.2%CVE-2026-67612MEDIUMOpenEMR 8.2.0 Stored XSS via import_template.php Template ManagementEPSS 0.1%CVE-2026-21443LOWOpenEMR allows inconsistent escaping of translation function outputEPSS 0.1%CVE-2026-40509MEDIUMOpenEMR < 8.3.0 CSRF via DICOM Viewer web_path ParameterEPSS 0.1%