Hl7 maintains healthcare data exchange standards and tooling including the C-CDA specification and FHIR IG Publisher, with a narrow but consequential footprint in clinical interoperability infrastructure. The observed vulnerability profile centers on application-layer input handling and information-disclosure weaknesses such as cross-site scripting, path traversal, and sensitive-data exposure, reflecting the document-processing and web-interface nature of these tools; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hl7 over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24057HIGH HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a | Jan 26, 2023 | 8.1 | 26 | NO | NO |
CVE-2014-5452MEDIUM CDA.xsl in HL7 C-CDA 1.1 and earlier does not anticipate the possibility of invalid C-CDA documents with crafted XML attributes, which allows remote attackers to conduct XSS attack | Sep 2, 2014 | 4.3 | 18 | NO | NO |
CVE-2014-3862MEDIUM CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an | Sep 2, 2014 | 4.3 | 14 | NO | NO |
CVE-2014-3861MEDIUM Cross-site scripting (XSS) vulnerability in CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted reference element with | Sep 2, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hl7.
Media articles that mention a CVE ID that affects a product developed by Hl7 — matched by CVE ID, not by vendor name.