Vulnerabilidades en openemr

131 resultados
Análisis Vexday

O OpenEMR acumula 120 CVEs catalogadas, com 7 classificadas como críticas e nenhuma confirmada em exploração ativa no catálogo CISA KEV, taxa abaixo da média geral do catálogo. Apesar da ausência de exploração ativa confirmada, o cenário merece atenção: CVE-2023-2948 apresenta score EPSS de 0,9673, indicando probabilidade muito elevada de exploração nos próximos 30 dias e devendo ser tratada como prioridade imediata de remediação. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), o que sugere fragilidades persistentes no tratamento de entradas do usuário na aplicação. A existência de PoC pública para ao menos uma vulnerabilidade eleva o risco operacional, especialmente em ambientes de saúde onde o sistema frequentemente lida com dados sensíveis de pacientes.

CVE-2026-33913HIGHOpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server FilesEPSS 0.3%CVE-2026-32118MEDIUMOpenEMR has Stored XSS in Graphical Pain Map legend via unescaped annotation textEPSS 0.3%CVE-2026-33321HIGHOpenEMR has Out-of-Band Server-Side Request Forgery (OOB SSRF)EPSS 0.3%CVE-2025-32967MEDIUMOpenEMR doesn't log password administration properlyEPSS 0.3%CVE-2026-25745MEDIUMOpenEMR's Message Update Ignores Patient idEPSS 0.3%CVE-2026-33933MEDIUMReflected XSS via Unescaped contextName Parameter in Custom Template EditorEPSS 0.3%CVE-2026-34056HIGHOpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only DataEPSS 0.3%CVE-2026-34055HIGHOpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modificationEPSS 0.3%CVE-2026-24487MEDIUMOpenEMR has FHIR Patient Compartment Bypass in CareTeam ResourceEPSS 0.3%CVE-2026-25124MEDIUMOpenEMR has Broken Access Control in Report/Clients/Message List CSV ExportEPSS 0.3%CVE-2026-25127HIGHOpenEMR has Broken Access Control on Care Coordination ModuleEPSS 0.3%CVE-2025-29772HIGHOpenEMR allows Reflected XSS in CAMOS new.phpEPSS 0.3%CVE-2026-32126HIGHOpenEMR: Inverted ACL Condition in CDR ControllerRouter Allows Any Authenticated User to Modify/Delete Clinical Rules and PlansEPSS 0.3%CVE-2026-27943MEDIUMOpenEMR's Eye Exam View Trusts form_id Without Verifying Patient/Encounter OwnershipEPSS 0.3%CVE-2026-24896MEDIUMOpenEMR has Broken Access Control that allows unauthorized access to EDI LogsEPSS 0.3%CVE-2026-25930MEDIUMOpenEMR's Printable LBF Endpoint Leaks Arbitrary Patient FormsEPSS 0.3%CVE-2026-25929MEDIUMOpenEMR Patient Picture Context Allows Arbitrary Patient Photo RetrievalEPSS 0.3%CVE-2026-25220MEDIUMOpenEMR Messages "Show All" Not Restricted to AdminsEPSS 0.3%CVE-2026-25164HIGHOpenEMR's Document and Insurance REST Endpoints Skip ACLEPSS 0.3%CVE-2026-32120MEDIUMOpenEMR has IDOR in Fee Sheet Product SaveEPSS 0.3%