Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32127 | 8.8 HIGH | SQL Injection Vulnerability in ajax graphs library (OpenEMR) |
| CVE-2026-32121 | 7.7 HIGH | OpenEMR: Stored DOM XSS via `.html()` in Portal Signer Modal |
| CVE-2026-32123 | 7.7 HIGH | OpenEMR: Therapy Group Sensitivity ACL No Longer Enforced |
| CVE-2026-32118 | 5.4 MEDIUM | OpenEMR has Stored XSS in Graphical Pain Map legend via unescaped annotation text |
| CVE-2026-32125 | 5.4 MEDIUM | OpenEMR: Stored XSS in Track Anything Graphs via Unescaped Dygraph Titles/Labels |
| CVE-2026-32124 | 5.4 MEDIUM | OpenEMR: Dynamic Code Picker Renders Unescaped Descriptions (Stored XSS) |
| CVE-2026-32122 | 4.3 MEDIUM | OpenEMR: Missing Authorization on Claim File Tracker UI and AJAX Endpoint (V2) |
No comments yet