Vulnerability index

Browse CVEs

28 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openmrs HIGH 8.8
CVE-2026-40076

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module …

Fix: after 2.8.5
Fix from $1,950 2026-05-06
Openmrs HIGH 7.5
CVE-2026-40075

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openm…

Fix: after 2.8.5
Fix from $1,950 2026-05-05
Openmrs HIGH 8.0
CVE-2025-25928

A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary opera…

No fix yet
Fix from $1,950 2025-03-11
Openmrs MEDIUM 6.8
CVE-2025-25927

A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.

No fix yet
Fix from $1,600 2025-03-11
Openmrs MEDIUM 5.4
CVE-2025-25929

A reflected cross-site scripting (XSS) vulnerability in the component /legacyui/quickReportServlet of Openmrs 2.4.3 Build 0ff0ed allows attackers to …

No fix yet
Fix from $1,600 2025-03-11
Admin Ui Module MEDIUM 6.1
CVE-2020-36636

A vulnerability classified as problematic has been found in OpenMRS Admin UI Module up to 1.4.x. Affected is the function sendErrorMessage of the fil…

Fix: 1.5.0+
Fix from $1,600 2022-12-27
Admin Ui Module MEDIUM 6.1
CVE-2021-4291

A vulnerability was found in OpenMRS Admin UI Module up to 1.5.x. It has been declared as problematic. This vulnerability affects unknown code of the…

Fix: 1.6.0+
Fix from $1,600 2022-12-27
Admin Ui Module MEDIUM 6.1
CVE-2021-4292

A vulnerability was found in OpenMRS Admin UI Module up to 1.4.x. It has been rated as problematic. This issue affects some unknown processing of the…

Fix: 1.5.0+
Fix from $1,600 2022-12-27
Appointment Scheduling Module MEDIUM 5.4
CVE-2020-36635

A vulnerability was found in OpenMRS Appointment Scheduling Module up to 1.12.x. It has been classified as problematic. This affects the function val…

Fix: 1.13.0+
Fix from $1,600 2022-12-27
Appointment Scheduling Module MEDIUM 6.1
CVE-2022-4727

A vulnerability, which was classified as problematic, was found in OpenMRS Appointment Scheduling Module up to 1.16.x. This affects the function getN…

Fix: 1.17.0+
Fix from $1,600 2022-12-27
Reference Application MEDIUM 6.1
CVE-2021-4288

A vulnerability was found in OpenMRS openmrs-module-referenceapplication up to 2.11.x. It has been rated as problematic. This issue affects some unkn…

Fix: 2.12.0+
Fix from $1,600 2022-12-27
Reference Application MEDIUM 6.1
CVE-2021-4289

A vulnerability classified as problematic was found in OpenMRS openmrs-module-referenceapplication up to 2.11.x. Affected by this vulnerability is th…

Fix: 2.12.0+
Fix from $1,600 2022-12-27
Htmlformentryui MEDIUM 6.1
CVE-2021-4284

A vulnerability classified as problematic has been found in OpenMRS HTML Form Entry UI Framework Integration Module up to 1.x. This affects an unknow…

Fix: 2.0.0+
Fix from $1,600 2022-12-27
Openmrs CRITICAL 9.8
CVE-2021-43094

An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via GET requ…

Fix: after 2.11
Fix from $2,300 2022-05-10
Openmrs HIGH 7.5
CVE-2022-23612

OpenMRS is a patient-based medical record system focusing on giving providers a free customizable electronic medical record system. Affected versions…

Fix: 2.1.5 / 2.2.1+
Fix from $1,950 2022-02-22
Htmlformentry HIGH 8.8
CVE-2020-24621

A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging…

Fix: 3.11.0+
Fix from $1,950 2020-09-25
Openmrs MEDIUM 6.1
CVE-2020-5732

In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user…

Fix: after 2.9.0
Fix from $1,600 2020-04-17
Openmrs MEDIUM 6.1
CVE-2020-5733

In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated use…

Fix: after 2.9.0
Fix from $1,600 2020-04-17
Openmrs MEDIUM 6.1
CVE-2020-5728

OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm). There is ins…

Fix: after 2.9.0
Fix from $1,600 2020-04-17
Openmrs MEDIUM 6.1
CVE-2020-5729

In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS. Any page …

Fix: after 2.9.0
Fix from $1,600 2020-04-17
Openmrs MEDIUM 6.1
CVE-2020-5730

In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting.

Fix: after 2.9.0
Fix from $1,600 2020-04-17
Openmrs MEDIUM 6.1
CVE-2020-5731

In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting.

Fix: after 2.9.0
Fix from $1,600 2020-04-17
Openmrs Module Htmlformentry CRITICAL 9.8
CVE-2017-12795

OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).

Patch available
Fix from $2,300 2019-05-10
Openmrs CRITICAL 9.8
CVE-2018-19276EPSS 99%

OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary comman…

Fix: 1.12.1 / 2.0.8+
Fix from $2,300 2019-03-21
Html Form Entry CRITICAL 9.8
CVE-2018-16521

An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.

Patch available
Fix from $2,300 2018-09-05
Openmrs CRITICAL 9.8
CVE-2017-12796

The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate user…

Fix: 2.6.1+
Fix from $2,300 2017-10-23
Openmrs Module Reporting HIGH 8.8
CVE-2017-7990

The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScri…

Patch available
Fix from $1,950 2017-04-21
Openmrs MEDIUM 6.8
CVE-2014-8073

Cross-site request forgery (CSRF) vulnerability in OpenMRS 2.1 Standalone Edition allows remote attackers to hijack the authentication of administrat…

No fix yet
Fix from $1,600 2014-10-23