Meddream develops PACS (Picture Archiving and Communication System) server software for medical imaging workflows, a specialized but critical healthcare IT component that processes and stores diagnostic images. The vendor's vulnerability footprint, while modest in volume, concentrates in a single product line serving a high-value, regulated environment where availability and data integrity matter significantly. Recurring weakness classes include input-validation failures such as cross-site scripting, buffer overflows in native components, cleartext transmission of sensitive information, and improper access controls—a pattern typical of legacy medical software balancing interoperability demands with security modernization. A meaningful share of the vendor's disclosures reach serious severity, reflecting the potential impact of flaws in healthcare infrastructure. Defenders should treat PACS server updates as priority fixes given the clinical role and the recurring authentication and data-protection weaknesses; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Meddream over time
Signals from CVEs in this vendor scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-27724CRITICAL A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file can lead to elevated capabilit | Jul 28, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-53912HIGH An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted HTTP request can lead to an arbitrary file | Jan 20, 2026 | 8.1 | 30 | NO | NO |
CVE-2025-26469CRITICAL An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDream PACS Premium 7.3.3.840.
A specially crafted application c | Jul 28, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-3484CRITICAL MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff | May 22, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-24485HIGH A server-side request forgery vulnerability exists in the cecho.php functionality of MedDream PACS Premium 7.3.5.860. A specially crafted HTTP request can lead to SSRF. An attacker | Jul 28, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-3483HIGH MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff | May 22, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-58094MEDIUM Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to | Jan 20, 2026 | 6.1 | 24 | NO | NO |
CVE-2025-57787MEDIUM A reflected cross-site scripting (xss) vulnerability exists in the modifyRoute functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbit | Jan 20, 2026 | 6.1 | 24 | NO | NO |
CVE-2025-55071MEDIUM A reflected cross-site scripting (xss) vulnerability exists in the modifyAnonymize functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to a | Jan 20, 2026 | 6.1 | 24 | NO | NO |
CVE-2025-53707MEDIUM A reflected cross-site scripting (xss) vulnerability exists in the modifyTranscript functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to | Jan 20, 2026 | 6.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (38 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Meddream.
Media articles that mention a CVE ID that affects a product developed by Meddream — matched by CVE ID, not by vendor name.