Openemr
Vendor:
First CVE: Jun 9, 2006 · Active for 20 years
224
Total CVEs
More Total CVEs than 83% of tracked products
14.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Openemr over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2006
20 years ago
Most Recent CVE
Jun 9, 2026
49 days ago
CVE Severity & Scoring
Openemr224 CVEs
55%
37%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (0.4%)
Network210 (93.8%)
Unknown13 (5.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low207 (92.4%)
High4 (1.8%)
Unknown13 (5.8%)
User Interaction
None134 (59.8%)
Unknown13 (5.8%)
Required77 (34.4%)
Privileges Required
Low135 (60.3%)
High21 (9.4%)
None55 (24.6%)
Unknown13 (5.8%)
Top CVEs
Signals from CVEs in this product scope (224 CVEs).
224 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2948MEDIUM Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1. | May 28, 2023 | 6.1 | 82 | NO | YES |
CVE-2022-2733MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1. | Aug 9, 2022 | 6.1 | 82 | NO | YES |
CVE-2019-14530HIGH An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) fr | Aug 13, 2019 | 8.8 | 81 | NO | YES |
CVE-2021-25921MEDIUM In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker c | Mar 22, 2021 | 5.4 | 67 | NO | NO |
CVE-2020-19364HIGH OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php. | Jan 20, 2021 | 8.8 | 66 | NO | NO |
CVE-2023-2947MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1. | May 27, 2023 | 4.8 | 65 | NO | NO |
CVE-2022-1179MEDIUM Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. | Mar 30, 2022 | 5.4 | 62 | NO | NO |
CVE-2020-36243HIGH The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can se | Feb 7, 2021 | 8.8 | 61 | NO | NO |
CVE-2018-15153HIGH OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/m | Aug 15, 2018 | 8.8 | 59 | NO | NO |
CVE-2020-13562MEDIUM A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker | Feb 1, 2021 | 6.1 | 56 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (224 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.9% of CVEs· Bottom 1%
Nuclei
5 CVEs
2.2% of CVEs· 98th percentile
ExploitDB
20 CVEs
8.9% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (224 CVEs).
Media Mentions
Signals from CVEs in this product scope (224 CVEs).
Top CNAs Publishing CVEs For Openemr
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0.3.4 | 1 | 6.5 | 0.4% | 0 | 0 |
| 7.0.3 | 1 | 8.8 | 0.3% | 0 | 0 |
| 7.0.2 | 2 | 9.8 | 3.4% | 0 | 0 |
| 7.0.1 | 2 | 6.2 | 0.4% | 0 | 0 |
| 6.0.0 | 6 | 6.7 | 7.0% | 0 | 1 |
| 5.0.2.1 | 5 | 8.0 | 13.7% | 0 | 0 |
| 5.0.2 | 8 | 7.6 | 33.5% | 0 | 0 |
| 5.0.1-6 | 2 | 6.7 | 24.8% | 0 | 0 |
| 5.0.1.4 | 2 | 5.4 | 0.9% | 0 | 0 |
| 5.0.1.3 | 1 | 8.8 | 0.6% | 0 | 0 |
| 5.0.1 | 2 | 7.5 | 35.9% | 0 | 0 |
| 5.0.0 | 3 | 7.5 | 1.9% | 0 | 0 |
| 4.2.0 | 1 | 5.0 | 2.9% | 0 | 0 |
| 4.1.2 | 1 | 5.0 | 2.9% | 0 | 0 |
| 4.1.1 | 5 | 5.4 | 2.1% | 0 | 3 |
| 4.1.0 | 5 | 5.6 | 4.3% | 0 | 4 |
| 4.0.0 | 4 | 5.9 | 2.1% | 0 | 3 |
| 3.2.0 | 2 | 6.3 | 2.5% | 0 | 1 |
| 3.1.0 | 2 | 6.3 | 2.5% | 0 | 1 |
| 3.0.1 | 1 | 5.0 | 2.9% | 0 | 0 |