OpenEMR is an open-source electronic health record system widely deployed across medical practices and healthcare facilities, creating a healthcare-facing attack surface that draws scrutiny from the security research community. Its vulnerability profile centers on the core OpenEMR application and recurs through weakness classes including code injection, improper input validation, and path traversal—characteristic of web applications handling sensitive clinical data and user input—and frequently acquires public exploit code that circulates among researchers and security practitioners. Defenders should treat OpenEMR instances as high-priority patching targets due to their healthcare context and exposure; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openemr over time
Signals from CVEs in this vendor scope (224 CVEs).
224 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2948MEDIUM Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1. | May 28, 2023 | 6.1 | 82 | NO | YES |
CVE-2022-2733MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1. | Aug 9, 2022 | 6.1 | 82 | NO | YES |
CVE-2019-14530HIGH An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) fr | Aug 13, 2019 | 8.8 | 81 | NO | YES |
CVE-2021-25921MEDIUM In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker c | Mar 22, 2021 | 5.4 | 67 | NO | NO |
CVE-2020-19364HIGH OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php. | Jan 20, 2021 | 8.8 | 66 | NO | NO |
CVE-2023-2947MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1. | May 27, 2023 | 4.8 | 65 | NO | NO |
CVE-2022-1179MEDIUM Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. | Mar 30, 2022 | 5.4 | 62 | NO | NO |
CVE-2020-36243HIGH The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can se | Feb 7, 2021 | 8.8 | 61 | NO | NO |
CVE-2018-15153HIGH OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/m | Aug 15, 2018 | 8.8 | 59 | NO | NO |
CVE-2020-13562MEDIUM A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker | Feb 1, 2021 | 6.1 | 56 | NO | NO |
Signals from CVEs in this vendor scope (224 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openemr.
Media articles that mention a CVE ID that affects a product developed by Openemr — matched by CVE ID, not by vendor name.