Where
-Infinity
0

Vendor Risk Score

See how open-emr compares to other vendors in security performance

View Risk Score →

OpenEMR OpenEMROpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics

Risk 61
Severity
8.7
First published (updated )

OpenEMR OpenEMROpenEMR 7.0.1 Authentication Brute Force Mitigation Bypass

Risk 47
Severity
8.7
First published (updated )

OpenEMR OpenEMROpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data

Risk 31
Severity
7.7
EPSS
0.02%
First published (updated )

OpenEMR OpenEMROpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification

Risk 43
Severity
8.1
EPSS
0.02%
First published (updated )

OpenEMR OpenEMROpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler

Risk 43
Severity
8.1
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenEMR OpenEMROpenEMR has Improper ACL On Import/Export Popup

Risk 25
Severity
5.4
EPSS
0.02%
First published (updated )

OpenEMR OpenEMROpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff Signatures

Risk 16
Severity
4.3
EPSS
0.04%
First published (updated )

OpenEMR OpenEMRReflected XSS via Unescaped contextName Parameter in Custom Template Editor

Risk 27
Severity
6.1
EPSS
0.02%
First published (updated )

OpenEMR OpenEMROpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes

Risk 36
Severity
7.6
EPSS
0.03%
First published (updated )

OpenEMR OpenEMROpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access

Risk 27
Severity
6.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenEMR OpenEMROpenEMR Missing Authorization on Claim File Download Endpoint

Risk 56
Severity
8.8
EPSS
0.03%
First published (updated )

OpenEMR OpenEMROpenEMR has SQL Injection in CAMOS Form

Risk 56
Severity
8.8
EPSS
0.00%
First published (updated )

OpenEMR OpenEMROpenEMR Missing ACL Checks on Insurance Company API Routes

Risk 25
Severity
5.4
EPSS
0.03%
First published (updated )

OpenEMR OpenEMROpenEMR has SQL Injection in PostCalendar Category Delete

Risk 49
Severity
7.2
EPSS
0.00%
First published (updated )

OpenEMR OpenEMROpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files

Risk 31
Severity
7.7
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenEMR OpenEMROpenEMR has reflected XSS in ajax_download.php via reportID parameter

Risk 25
Severity
5.4
EPSS
0.03%
First published (updated )

OpenEMR OpenEMROpenEMR vulnerable to reflected XSS in graphs.php via title parameter

Risk 25
Severity
5.4
EPSS
0.03%
First published (updated )

OpenEMR OpenEMROpenEMR has a SQL Injection Vulnerability in patient selection

Risk 56
Severity
8.8
EPSS
0.00%
First published (updated )

OpenEMR OpenEMROpenEMR Vulnerable to SQL Injection via Unsanitized Variables in MedEx Recall/Reminder Processing

Risk 34
Severity
5.9
EPSS
0.00%
First published (updated )

OpenEMR OpenEMROpenEMR has Stored XSS in patient encounter Eye Exam form $CHRONIC2 and $CHRONIC3

Risk 61
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenEMR OpenEMROpenEMR has IDOR in Fee Sheet Product Save

Risk 38
Severity
6.5
First published (updated )

OpenEMR OpenEMROpenEMR Vulnerable to Authenticated Blind Boolean-Based SQL Injection in new_search_popup.php

Risk 79
Severity
8.8
First published (updated )

OpenEMR OpenEMROpenEMR has stored XSS in portal_payment.php via Unescaped table_args

Risk 45
Severity
8.7
EPSS
0.04%
First published (updated )

OpenEMR OpenEMROpenEMR has Authorization Bypass in FaxSMS AppDispatch Constructor

Risk 25
Severity
5.4
EPSS
0.06%
First published (updated )

OpenEMR OpenEMROpenEMR has Authorization Bypass in Dated Reminders Log

Risk 27
Severity
6.5
EPSS
0.08%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenEMR OpenEMROpenEMR Vulnerable to Stored XSS via Unescaped portal_login_username in Credential Print View

Risk 25
Severity
5.4
EPSS
0.04%
First published (updated )

OpenEMR OpenEMROpenEMR: zhAclCheck Ignores Explicit ACL Denies

Risk 43
Severity
7.3
EPSS
0.10%
First published (updated )

OpenEMR OpenEMROpenEMR has Out-of-Band Server-Side Request Forgery (OOB SSRF)

Risk 42
Severity
7.2
EPSS
0.10%
First published (updated )

OpenEMR OpenEMROpenEMR has arbitrary image file read via PDF generator

Risk 43
Severity
7.1
EPSS
0.11%
First published (updated )

OpenEMR OpenEMROpenEMR has Stored XSS in patient encounter Eye Exam form answers

Risk 43
Severity
8.5
EPSS
0.17%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203