Vulnerabilidades en OpenEMR
131 resultadosAnálisis Vexday
OpenEMR possui apenas 1 vulnerabilidade registrada na base, classificada como injeção SQL (CWE-89), sem evidências de ataque ativo ou severidade crítica. O risco atual é baixo, mas a natureza da fraqueza—injeção SQL—demanda atenção contínua em atualizações de segurança, especialmente em ambientes clínicos que armazenam dados sensíveis.
CVE-2022-4506HIGHUnrestricted Upload of File with Dangerous Type in openemr/openemrEPSS 1.0%CVE-2022-2732HIGHMissing Authorization in openemr/openemrEPSS 0.9%CVE-2022-1461HIGHNon Privilege User can Enable or Disable Registered in openemr/openemrEPSS 0.9%CVE-2022-1177MEDIUMAccounting User Can Download Patient Reports in openemr in openemr/openemrEPSS 0.9%CVE-2022-4504HIGHImproper Input Validation in openemr/openemrEPSS 0.9%CVE-2025-29789MEDIUMOpenEMR Has Directory Traversal in Load Code featureEPSS 0.8%CVE-2022-2734CRITICALImproper Restriction of Rendered UI Layers or Frames in openemr/openemrEPSS 0.8%CVE-2023-2942HIGHImproper Input Validation in openemr/openemrEPSS 0.8%CVE-2022-2730MEDIUMAuthorization Bypass Through User-Controlled Key in openemr/openemrEPSS 0.8%CVE-2026-23627HIGHOpenEMR has SQL Injection in Immunization Search/ReportEPSS 0.8%CVE-2022-2824HIGHAuthorization Bypass Through User-Controlled Key in openemr/openemrEPSS 0.7%CVE-2022-1458HIGHStored XSS Leads To Session Hijacking in openemr/openemrEPSS 0.7%CVE-2022-4505HIGHAuthorization Bypass Through User-Controlled Key in openemr/openemrEPSS 0.7%CVE-2022-4615HIGHCross-site Scripting (XSS) - Reflected in openemr/openemrEPSS 0.7%CVE-2022-2494MEDIUMCross-site Scripting (XSS) - Stored in openemr/openemrEPSS 0.6%CVE-2022-4502HIGHCross-site Scripting (XSS) - Reflected in openemr/openemrEPSS 0.6%CVE-2023-2943MEDIUMCode Injection in openemr/openemrEPSS 0.6%CVE-2023-2674HIGHImproper Access Control in openemr/openemrEPSS 0.6%CVE-2022-4567HIGHImproper Access Control in openemr/openemrEPSS 0.6%CVE-2022-1180MEDIUMReflected Cross Site Scripting in openemr/openemrEPSS 0.6%