Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openemr

First CVE: Jun 9, 2006Active for: 20 yearsTotal CVEs: 224

OpenEMR is an open-source electronic health record system widely deployed across medical practices and healthcare facilities, creating a healthcare-facing attack surface that draws scrutiny from the security research community. Its vulnerability profile centers on the core OpenEMR application and recurs through weakness classes including code injection, improper input validation, and path traversal—characteristic of web applications handling sensitive clinical data and user input—and frequently acquires public exploit code that circulates among researchers and security practitioners. Defenders should treat OpenEMR instances as high-priority patching targets due to their healthcare context and exposure; current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
224
Total CVEs
More Total CVEs than 86% of tracked vendors
14.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openemr over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2006
20 years ago
Most Recent CVE
Jun 9, 2026
45 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (224 CVEs).

224 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-2948MEDIUM
Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.
May 28, 20236.182NOYES
CVE-2022-2733MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.
Aug 9, 20226.182NOYES
CVE-2019-14530HIGH
An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) fr
Aug 13, 20198.881NOYES
CVE-2021-25921MEDIUM
In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker c
Mar 22, 20215.467NONO
CVE-2020-19364HIGH
OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.
Jan 20, 20218.866NONO
CVE-2023-2947MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.
May 27, 20234.865NONO
CVE-2022-1179MEDIUM
Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
Mar 30, 20225.462NONO
CVE-2020-36243HIGH
The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can se
Feb 7, 20218.861NONO
CVE-2018-15153HIGH
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/m
Aug 15, 20188.859NONO
CVE-2020-13562MEDIUM
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker
Feb 1, 20216.156NONO
View all 224 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products224 CVEs
55%
37%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (0.4%)
Network210 (93.8%)
Unknown13 (5.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low207 (92.4%)
High4 (1.8%)
Unknown13 (5.8%)
User Interaction
None134 (59.8%)
Unknown13 (5.8%)
Required77 (34.4%)
Privileges Required
Low135 (60.3%)
High21 (9.4%)
None55 (24.6%)
Unknown13 (5.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (224 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.9% of CVEs· Bottom 1%
Nuclei
5 CVEs
2.2% of CVEs· 97th percentile
ExploitDB
20 CVEs
8.9% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openemr.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openemr — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openemr's Products

View all 8 CNAs →

Top CWEs