Known Vulnerabilities for products from Open-Emr
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Open-Emr".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-88002 json | Not Provided | 2026-09-09 | 2026-09-09 | |
| CVE-2026-88001 json | Not Provided | 2026-09-09 | 2026-09-09 | |
| CVE-2026-88000 json | Not Provided | 2026-09-09 | 2026-09-09 | |
| CVE-2026-87999 json | Not Provided | 2026-09-09 | 2026-09-09 | |
| CVE-2026-87998 json | Not Provided | 2026-09-09 | 2026-09-09 | |
| CVE-2026-87997 json | Not Provided | 2026-09-09 | 2026-09-09 | |
| CVE-2026-87996 json | Not Provided | 2026-09-09 | 2026-09-09 | |
| CVE-2026-87995 json | Not Provided | 2026-09-09 | 2026-09-09 | |
| CVE-2026-87994 json | Not Provided | 2026-09-09 | 2026-09-09 | |
| CVE-2026-87017 json | Not Provided | 2026-09-09 | 2026-09-09 | |
| CVE-2026-67611 json | OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumv... | Not Provided | 2026-08-03 | 2026-09-01 |
| CVE-2026-46518 json | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0... | Not Provided | 2026-06-10 | 2026-07-23 |
| CVE-2026-39932 json | OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes... | Not Provided | 2026-08-03 | 2026-09-01 |
| CVE-2026-39931 json | OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that a... | Not Provided | 2026-08-03 | 2026-09-01 |
| CVE-2023-54347 json | OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protections ... | Not Provided | 2026-05-05 | 2026-05-05 |
| CVE-2023-22974 json | A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a... | 7.5 - HIGH | 2023-02-22 | 2023-03-03 |
| CVE-2023-22973 json | A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated user... | 8.8 - HIGH | 2023-02-22 | 2023-03-03 |
| CVE-2023-22972 json | A Reflected Cross-site scripting (XSS) vulnerability in interface/forms/eye_mag/php/eye_mag_functions.php in OpenEMR < 7.0.0 ... | 5.4 - MEDIUM | 2023-02-22 | 2023-03-03 |
| CVE-2023-2950 json | Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1. | 8.1 - HIGH | 2023-05-28 | 2023-06-01 |
| CVE-2023-2949 json | Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1. | 6.1 - MEDIUM | 2023-05-28 | 2023-06-01 |
Known software with vulnerabilities from Open-Emr
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Open-emr | Openemr | 2.0.1.2 |