Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openclinic Ga Project

First CVE: Jul 20, 2020Active for: 6 yearsTotal CVEs: 38
58.9
VTI Score
TOP TARGET

Openclinic GA is a modestly represented, open-source healthcare management application that serves as a deployable platform for clinical operations and patient records, presenting a concentrated but notable attack surface in the medical-software domain. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across its single primary product through web-application and data-handling weakness classes: SQL injection, cross-site scripting, improper authentication, path traversal, and exposure of sensitive information. These flaws are characteristic of web-facing applications handling protected health information and administrative functions, where input validation, access control, and data-protection boundaries are fundamental to security. Defenders deploying this platform should prioritize patching and institute strict input validation, access controls, and network segmentation around instances handling patient data; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
38
Total CVEs
More Total CVEs than 98% of tracked vendors
9.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
8.7
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openclinic Ga Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 20, 2020
6 years ago
Most Recent CVE
Jun 9, 2026
49 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-40279HIGH
An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do.
Mar 19, 20247.532NOYES
CVE-2023-40278HIGH
An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changin
Mar 19, 20247.531NOYES
CVE-2020-27238CRITICAL
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the getAssets.jsp page is vulnerable to unauthenticated SQ
Apr 15, 20219.831NONO
CVE-2020-14494CRITICAL
OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks
Jul 20, 20209.831NONO
CVE-2020-27241CRITICAL
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The serialnumber parameter in the getAssets.jsp page is vulnerable to unauthenti
Apr 19, 20219.830NONO
CVE-2020-27240CRITICAL
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The componentStatus parameter in the getAssets.jsp page is vulnerable to unauthe
Apr 19, 20219.830NONO
CVE-2020-14485CRITICAL
OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted request to initiate a session with limited functionality, w
Jul 20, 20209.830NONO
CVE-2026-25860MEDIUM
OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's
Jun 9, 20266.129NONO
CVE-2020-27237CRITICAL
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the The nomenclature parameter in the getAssets.jsp page i
Apr 15, 20219.829NONO
CVE-2023-40276CRITICAL
An issue was discovered in OpenClinic GA 5.247.01. An Unauthenticated File Download vulnerability has been discovered in pharmacy/exportFile.jsp.
Mar 19, 20249.128NONO
View all 38 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products38 CVEs
11%
50%
39%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (5.3%)
Network36 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None33 (86.8%)
Unknown0 (0.0%)
Required5 (13.2%)
Privileges Required
Low14 (36.8%)
High0 (0.0%)
None24 (63.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
5.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openclinic Ga Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openclinic Ga Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openclinic Ga Project's Products

View all 4 CNAs →

Top CWEs