Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33917 | 8.8 HIGH | OpenEMR has SQL Injection in CAMOS Form |
| CVE-2026-29187 | 8.1 HIGH | OpenEMR Vulnerable to Authenticated Blind Boolean-Based SQL Injection in new_search_popup. |
| CVE-2026-34055 | 8.1 HIGH | OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification |
| CVE-2026-34056 | 7.7 HIGH | OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data |
| CVE-2026-33913 | 7.7 HIGH | OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files |
| CVE-2026-33918 | 7.6 HIGH | OpenEMR Missing Authorization on Claim File Download Endpoint |
| CVE-2026-33932 | 7.6 HIGH | OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes |
| CVE-2026-33910 | 7.2 HIGH | OpenEMR has a SQL Injection Vulnerability in patient selection |
| CVE-2026-33914 | 7.2 HIGH | OpenEMR has SQL Injection in PostCalendar Category Delete |
| CVE-2026-34053 | 7.1 HIGH | OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler |
| CVE-2026-33931 | 6.5 MEDIUM | OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access |
| CVE-2026-32120 | 6.5 MEDIUM | OpenEMR has IDOR in Fee Sheet Product Save |
| CVE-2026-33933 | 6.1 MEDIUM | Reflected XSS via Unescaped contextName Parameter in Custom Template Editor |
| CVE-2026-33909 | 5.9 MEDIUM | OpenEMR Vulnerable to SQL Injection via Unsanitized Variables in MedEx Recall/Reminder Pro |
| CVE-2026-33912 | 5.4 MEDIUM | OpenEMR has reflected XSS in ajax_download.php via reportID parameter |
| CVE-2026-33911 | 5.4 MEDIUM | OpenEMR vulnerable to reflected XSS in graphs.php via title parameter |
| CVE-2026-33915 | 5.4 MEDIUM | OpenEMR Missing ACL Checks on Insurance Company API Routes |
| CVE-2026-34051 | 5.4 MEDIUM | OpenEMR has Improper ACL On Import/Export Popup |
| CVE-2026-33934 | 4.3 MEDIUM | OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff |
No comments yet