OpenDental is a dental practice management software platform serving small and mid-sized dental offices, and its vulnerability profile centers on credential and data-protection weaknesses including insufficiently protected credentials, weak password requirements, and password-hashing deficiencies that threaten patient and practice data. These recurring issues reflect common challenges in practice-management software where sensitive patient records and payment data must be protected against both internal and external threats. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opendental over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-6531CRITICAL Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative access by leveraging access to intranet TCP port 3306. NOT | Sep 24, 2016 | 9.8 | 31 | NO | NO |
CVE-2018-15719CRITICAL Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank password. This allows anyone on the network with access to the ser | Dec 12, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-15718HIGH Open Dental before version 18.4 transmits the entire user database over the network when a remote unauthenticated user accesses the command prompt. This allows the attacker to gain | Dec 12, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-15717MEDIUM Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes. | Dec 12, 2018 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opendental.
Media articles that mention a CVE ID that affects a product developed by Opendental — matched by CVE ID, not by vendor name.