Open Emr is a widely deployed open-source electronic health record platform that has accumulated a large vulnerability footprint despite a minimal product portfolio, reflecting the complexity of healthcare-specific software and the breadth of its deployment across clinical environments. The vendor's disclosure history spans a diverse array of application-layer flaws across its monolithic codebase, and the exposure surfaces the particular challenges of maintaining security in systems that handle sensitive patient data and integrate deeply with healthcare workflows. The lack of a coherent pattern across recurring weakness classes underscores the distributed nature of the vulnerabilities—each represents a distinct context rather than a structural or architectural deficiency. Defenders relying on this platform should establish robust patch-management discipline and treat updates as operationally urgent, particularly for internet-reachable instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Open Emr over time
Signals from CVEs in this vendor scope (224 CVEs).
224 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2948MEDIUM Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1. | May 28, 2023 | 6.1 | 82 | NO | YES |
CVE-2022-2733MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1. | Aug 9, 2022 | 6.1 | 82 | NO | YES |
CVE-2019-14530HIGH An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) fr | Aug 13, 2019 | 8.8 | 81 | NO | YES |
CVE-2021-25921MEDIUM In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker c | Mar 22, 2021 | 5.4 | 67 | NO | NO |
CVE-2020-19364HIGH OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php. | Jan 20, 2021 | 8.8 | 66 | NO | NO |
CVE-2023-2947MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1. | May 27, 2023 | 4.8 | 65 | NO | NO |
CVE-2022-1179MEDIUM Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. | Mar 30, 2022 | 5.4 | 62 | NO | NO |
CVE-2020-36243HIGH The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can se | Feb 7, 2021 | 8.8 | 61 | NO | NO |
CVE-2018-15153HIGH OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/m | Aug 15, 2018 | 8.8 | 59 | NO | NO |
CVE-2020-13562MEDIUM A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker | Feb 1, 2021 | 6.1 | 56 | NO | NO |
Signals from CVEs in this vendor scope (224 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Open Emr.
Media articles that mention a CVE ID that affects a product developed by Open Emr — matched by CVE ID, not by vendor name.