Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Openemr HIGH 7.5
CVE-2023-54347

OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protections by sending repeated logi…

No fix yet
Fix from $1,950 2026-05-05
Openemr CRITICAL 9.8
CVE-2024-22611EPSS 6%

OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controll…

No fix yet
Fix from $2,300 2025-04-03
Openemr CRITICAL 9.8
CVE-2020-13567

Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an …

No fix yet
Fix from $2,300 2022-04-18
Openemr MEDIUM 5.4
CVE-2022-24643

A stored cross-site scripting (XSS) issue was discovered in the OpenEMR Hospital Information Management System version 6.0.0.

No fix yet
Fix from $1,600 2022-03-25
Openemr HIGH 8.1
CVE-2022-25471

An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas v…

Mitigation only
Fix from $1,950 2022-03-03
Openemr MEDIUM 6.5
CVE-2021-41843EPSS 14%

An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables …

No fix yet
Fix from $1,600 2021-12-17
Openemr MEDIUM 6.5
CVE-2021-40352EPSS 10%

OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.

No fix yet
Fix from $1,600 2021-09-01
Openemr HIGH 8.2
CVE-2021-32101

The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerab…

Mitigation only
Fix from $1,950 2021-05-07
Openemr HIGH 8.8
CVE-2020-13566

SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP requ…

No fix yet
Fix from $1,950 2021-04-13
Openemr HIGH 8.8
CVE-2020-13568EPSS 30%

SQL injection vulnerability exists in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP reque…

No fix yet
Fix from $1,950 2021-04-13
Openemr MEDIUM 6.1
CVE-2020-13565

An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development version 6.…

No fix yet
Fix from $1,600 2021-02-10
Openemr HIGH 8.8
CVE-2020-13569

A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f…

No fix yet
Fix from $1,950 2021-01-28
Openemr HIGH 8.8
CVE-2020-19364EPSS 71%

OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.

No fix yet
Fix from $1,950 2021-01-20
Openemr HIGH 8.8
CVE-2018-16795

OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_…

No fix yet
Fix from $1,950 2020-12-31
Openemr MEDIUM 6.1
CVE-2019-8368EPSS 47%

OpenEMR v5.0.1-6 allows XSS.

No fix yet
Fix from $1,600 2019-09-16
Openemr HIGH 7.2
CVE-2019-8371

OpenEMR v5.0.1-6 allows code execution.

No fix yet
Fix from $1,950 2019-09-16
Openemr MEDIUM 5.4
CVE-2018-1000218

OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that c…

No fix yet
Fix from $1,600 2018-08-20
Openemr MEDIUM 5.4
CVE-2018-1000219

OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that c…

No fix yet
Fix from $1,600 2018-08-20
Openemr MEDIUM 6.1
CVE-2017-6394

Multiple Cross-Site Scripting (XSS) issues were discovered in OpenEMR 5.0.0 and 5.0.1-dev. The vulnerabilities exist due to insufficient filtration o…

No fix yet
Fix from $1,600 2017-03-02
Openemr MEDIUM 6.8
CVE-2011-5161

Unrestricted file upload vulnerability in the patient photograph functionality in OpenEMR 4 allows remote attackers to execute arbitrary PHP code by …

No fix yet
Fix from $1,600 2012-09-09