Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

OpenEMR — Vulnerabilities & Security Advisories 120

Browse all 120 CVE security advisories affecting OpenEMR. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenEMR is an open-source electronic health record and medical practice management application designed to facilitate patient data management and clinical workflows. Historically, its codebase has exhibited significant security flaws, with over 120 Common Vulnerabilities and Exposures (CVEs) recorded. These vulnerabilities predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and improper access controls within the PHP-based architecture. Notable incidents include critical flaws allowing unauthenticated attackers to execute arbitrary commands or bypass authentication mechanisms, exposing sensitive patient information. The high volume of historical CVEs reflects challenges in maintaining rigorous security standards across a large, community-driven codebase. While recent updates have addressed many issues, the application’s complexity and extensive feature set continue to present attack surfaces that require diligent patching and configuration hardening to mitigate risks associated with data breaches and unauthorized system access.

Top products by OpenEMR: OpenEMR openemr/openemr
MediumCVE-2026-279432026-02-26
Eye Exam View Trusts form_id Without Verifying Patient/Encounter Ownership · Advisory · openemr/openemr · GitHub
High2026-02-26
SQL Injection Vulnerability in OpenEMR <8.0.0 · Advisory · openemr/openemr · GitHub
HighCVE-2026-259272026-02-26
Missing Authorization Checks in DICOM Viewer State API · Advisory · openemr/openemr · GitHub
MediumCVE-2026-259292026-02-26
Patient Picture Context Allows Arbitrary Patient Photo Retrieval · Advisory · openemr/openemr · GitHub
MediumCVE-2026-259302026-02-26
Printable LBF Endpoint Leaks Arbitrary Patient Forms · Advisory · openemr/openemr · GitHub
HighCVE-2026-257432026-02-26
Stored XSS in Questionnaire answers · Advisory · openemr/openemr · GitHub
MediumCVE-2026-252202026-02-26
Messages "Show All" Not Restricted to Admins · Advisory · openemr/openemr · GitHub
High2026-02-26
Merge commit from fork · openemr/openemr@cbf4ea4 · GitHub
CriticalCVE-2026-249082026-02-26
SQL Injection in Patient API Sort Parameter · Advisory · openemr/openemr · GitHub
HighCVE-2026-254762026-02-26
Session Timeout Bypass via skip_timeout_reset · Advisory · openemr/openemr · GitHub
CriticalCVE-2026-236272026-02-26
SQL Injection in Immunization Search/Report · Advisory · openemr/openemr · GitHub
MediumCVE-2026-251352026-02-25
Information Disclosure: Location resource for Group.$export operation returns entire patient/user population contact inf
HighCVE-2026-251272026-02-25
Broken Access Control on Care Coordination Module · Advisory · openemr/openemr · GitHub
HighCVE-2026-251312026-02-25
Broken Access Control in Procedures Configuration · Advisory · openemr/openemr · GitHub
Medium2026-02-25
Broken Access Control in OpenEMR allows unauthorized access to EDI Logs · Advisory · openemr/openemr · GitHub
High2026-02-25
Merge commit from fork · openemr/openemr@5f20b75 · GitHub
MediumCVE-2026-251242026-02-25
Broken Access Control in Report/Clients/Message List CSV Export · Advisory · openemr/openemr · GitHub
HighCVE-2025-682772026-02-25
Links sent via Secure Messaging open in OpenEMR and Portal · Advisory · openemr/openemr · GitHub
HighCVE-2025-677522026-02-25
Disabled SSL Certificate Verification in HTTP Client · Advisory · openemr/openemr · GitHub
HighCVE-2025-543732026-01-28
Contents of Clinical Notes and Care Plan, where an encounter has Sensitivity=high, can be viewed and changed by users wh

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with OpenEMR. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.