Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Open Emr

First CVE: Jun 9, 2006Active for: 20 yearsTotal CVEs: 224

Open Emr is a widely deployed open-source electronic health record platform that has accumulated a large vulnerability footprint despite a minimal product portfolio, reflecting the complexity of healthcare-specific software and the breadth of its deployment across clinical environments. The vendor's disclosure history spans a diverse array of application-layer flaws across its monolithic codebase, and the exposure surfaces the particular challenges of maintaining security in systems that handle sensitive patient data and integrate deeply with healthcare workflows. The lack of a coherent pattern across recurring weakness classes underscores the distributed nature of the vulnerabilities—each represents a distinct context rather than a structural or architectural deficiency. Defenders relying on this platform should establish robust patch-management discipline and treat updates as operationally urgent, particularly for internet-reachable instances; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
224
Total CVEs
More Total CVEs than 100% of tracked vendors
14.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Open Emr over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2006
20 years ago
Most Recent CVE
Jun 9, 2026
45 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (224 CVEs).

224 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-2948MEDIUM
Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.
May 28, 20236.182NOYES
CVE-2022-2733MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.
Aug 9, 20226.182NOYES
CVE-2019-14530HIGH
An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) fr
Aug 13, 20198.881NOYES
CVE-2021-25921MEDIUM
In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker c
Mar 22, 20215.467NONO
CVE-2020-19364HIGH
OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.
Jan 20, 20218.866NONO
CVE-2023-2947MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.
May 27, 20234.865NONO
CVE-2022-1179MEDIUM
Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
Mar 30, 20225.462NONO
CVE-2020-36243HIGH
The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can se
Feb 7, 20218.861NONO
CVE-2018-15153HIGH
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/m
Aug 15, 20188.859NONO
CVE-2020-13562MEDIUM
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker
Feb 1, 20216.156NONO
View all 224 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products224 CVEs
55%
37%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (0.4%)
Network210 (93.8%)
Unknown13 (5.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low207 (92.4%)
High4 (1.8%)
Unknown13 (5.8%)
User Interaction
None134 (59.8%)
Unknown13 (5.8%)
Required77 (34.4%)
Privileges Required
Low135 (60.3%)
High21 (9.4%)
None55 (24.6%)
Unknown13 (5.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (224 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.9% of CVEs· 97th percentile
Nuclei
5 CVEs
2.2% of CVEs· 95th percentile
ExploitDB
20 CVEs
8.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Open Emr.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Open Emr — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Open Emr's Products

View all 8 CNAs →

Top CWEs