« Volver al listado

Open-emr

Open-emr Openemr: vulnerabilidades y CVE

Open-emr Openemr tiene 221 vulnerabilidades publicadas, 79 de ellas en los últimos 12 meses. 14 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE221
Últimos 12 meses79
Críticas14
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-67611Alta (8.6)0.78%—3 ago 2026
OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through…
CVE-2026-39932Crítica (9.4)2.0%—3 ago 2026
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating…
CVE-2026-39931Alta (8.6)0.64%—3 ago 2026
OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to execute arbitrary DDL and DML…
CVE-2026-46518Alta (8.7)0.80%—10 jun 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-site scripting vulnerability in the prescription CSS/HTML multi-print…
CVE-2023-54347Alta (8.7)0.54%—5 may 2026
OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protections by sending repeated login attempts to the main login endpoint. Attackers can submit POST…
CVE-2026-34056Media (6.5)0.36%—26 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access Control vulnerability in OpenEMR up to and including version 8.0.0.3 allows low-privilege users to…
CVE-2026-34055Media (6.3)0.36%—26 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient notes functions in `library/pnotes.inc.php` perform updates and…
CVE-2026-34053Alta (8.1)0.62%—26 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the AJAX deletion endpoint…
CVE-2026-34051Media (5.4)0.30%—26 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper access control on the Import/Export functionality, allowing…
CVE-2026-33934Media (4.3)0.41%—26 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have a missing authorization check in `portal/sign/lib/show-signature.php` that allows…
CVE-2026-33933Media (6.1)0.92%—26 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to version 8.0.0.3, a reflected cross-site scripting (XSS) vulnerability in…
CVE-2026-33932Media (5.4)0.32%—26 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-site scripting vulnerability in the CCDA document preview allows an…
CVE-2026-33931Media (6.5)0.50%—26 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment…
CVE-2026-33918Alta (8.8)0.45%—26 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-download endpoint `interface/billing/get_claim_file.php` only verifies…
CVE-2026-33917Alta (8.8)0.63%—26 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contais a SQL injection vulnerability in the ajax_save CAMOS form that can be exploited…
CVE-2026-33915Media (5.4)0.29%—26 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, five insurance company REST API routes are missing the…
CVE-2026-33914Alta (7.2)0.52%—26 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the PostCalendar module contains a blind SQL injection vulnerability in the…
CVE-2026-33913Media (4.9)0.51%—25 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted…
CVE-2026-33912Media (5.4)0.30%—25 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated attacker could craft a malicious form that, when submitted by a victim,…
CVE-2026-33911Media (5.4)0.29%—25 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the POST parameter `title` is reflected back in a JSON response built with…
CVE-2026-33910Alta (8.8)0.64%—25 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Versions up to and including 8.0.0.2 contain a SQL injection vulnerability in the patient selection feature that…
CVE-2026-33909Media (5.9)0.39%—25 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, several variables in the MedEx recall/reminder processing code are concatenated directly…
CVE-2026-33348Media (5.4)0.95%—25 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form…
CVE-2026-32120Media (6.3)0.38%—25 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the fee sheet product save…
CVE-2026-29187Alta (8.8)0.64%—25 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a Blind SQL Injection vulnerability exists in the Patient Search functionality…
CVE-2026-33346Alta (8.7)1.0%—19 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, a stored cross-site scripting (XSS) vulnerability in the patient portal payment flow allows a…
CVE-2026-33321Alta (7.2)0.33%—19 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The…
CVE-2026-33305Media (5.4)0.31%—19 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the optional FaxSMS module (`oe-module-faxsms`) allows any…
CVE-2026-33304Media (6.5)0.44%—19 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the dated reminders log allows any authenticated non-admin user to…
CVE-2026-33303Media (5.4)0.65%—19 mar 2026
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 are vulnerable to stored cross-site scripting (XSS) via unescaped…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services27
  2. T1005 Data from Local System12
  3. T1059.007 JavaScript8
  4. T1189 Drive-by Compromise8
  5. T1078 Valid Accounts6
  6. T1059 Command and Scripting Interpreter3

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.