Openclinic GA is a modestly represented, open-source healthcare management application that serves as a deployable platform for clinical operations and patient records, presenting a concentrated but notable attack surface in the medical-software domain. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across its single primary product through web-application and data-handling weakness classes: SQL injection, cross-site scripting, improper authentication, path traversal, and exposure of sensitive information. These flaws are characteristic of web-facing applications handling protected health information and administrative functions, where input validation, access control, and data-protection boundaries are fundamental to security. Defenders deploying this platform should prioritize patching and institute strict input validation, access controls, and network segmentation around instances handling patient data; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openclinic Ga Project over time
Signals from CVEs in this vendor scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-40279HIGH An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do. | Mar 19, 2024 | 7.5 | 32 | NO | YES |
CVE-2023-40278HIGH An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changin | Mar 19, 2024 | 7.5 | 31 | NO | YES |
CVE-2020-27238CRITICAL An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the getAssets.jsp page is vulnerable to unauthenticated SQ | Apr 15, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-14494CRITICAL OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks | Jul 20, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-27241CRITICAL An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The serialnumber parameter in the getAssets.jsp page is vulnerable to unauthenti | Apr 19, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-27240CRITICAL An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The componentStatus parameter in the getAssets.jsp page is vulnerable to unauthe | Apr 19, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-14485CRITICAL OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted request to initiate a session with limited functionality, w | Jul 20, 2020 | 9.8 | 30 | NO | NO |
CVE-2026-25860MEDIUM OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's | Jun 9, 2026 | 6.1 | 29 | NO | NO |
CVE-2020-27237CRITICAL An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the The nomenclature parameter in the getAssets.jsp page i | Apr 15, 2021 | 9.8 | 29 | NO | NO |
CVE-2023-40276CRITICAL An issue was discovered in OpenClinic GA 5.247.01. An Unauthenticated File Download vulnerability has been discovered in pharmacy/exportFile.jsp. | Mar 19, 2024 | 9.1 | 28 | NO | NO |
Signals from CVEs in this vendor scope (38 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openclinic Ga Project.
Media articles that mention a CVE ID that affects a product developed by Openclinic Ga Project — matched by CVE ID, not by vendor name.