6.5

CVSS3.1

CVE-2026-33931 - OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment page allows any authenticated portal patient to access other patients' payment re…

πŸ“… Published: March 25, 2026, 11:36 p.m. πŸ”„ Last Modified: March 27, 2026, 9:29 a.m.

5.3

CVSS4.0

CVE-2026-4826 - SourceCodester Sales and Inventory System HTTP GET Parameter update_stock.php sql injection

A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /update_stock.php of the component HTTP GET Parameter Handler. This manipulation of the argument sid causes sql injection. Remote exploitation of the attack is possib…

πŸ“… Published: March 25, 2026, 11:35 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

7.6

CVSS3.1

CVE-2026-33918 - OpenEMR Missing Authorization on Claim File Download Endpoint

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-download endpoint `interface/billing/get_claim_file.php` only verifies that the caller has a valid session and CSRF token, but does not check any ACL p…

πŸ“… Published: March 25, 2026, 11:35 p.m. πŸ”„ Last Modified: March 27, 2026, 9:29 a.m.

8.8

CVSS3.1

CVE-2026-33917 - OpenEMR has SQL Injection in CAMOS Form

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contais a SQL injection vulnerability in the ajax_save CAMOS form that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input v…

πŸ“… Published: March 25, 2026, 11:31 p.m. πŸ”„ Last Modified: March 27, 2026, 9:29 a.m.

8.8

CVSS3.1

CVE-2026-4758 - WP Job Portal <= 2.4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File…

The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfields::removeFileCustom' function in all versions up to, and including, 2.4.9. This makes it possible for authenticated attackers, with Subscriber-level…

πŸ“… Published: March 25, 2026, 11:26 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

5.4

CVSS3.1

CVE-2026-33915 - OpenEMR Missing ACL Checks on Insurance Company API Routes

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, five insurance company REST API routes are missing the `RestConfig::request_authorization_check()` call that every other data-modifying route in the standard API uses. …

πŸ“… Published: March 25, 2026, 11:23 p.m. πŸ”„ Last Modified: March 27, 2026, 9:29 a.m.

7.2

CVSS3.1

CVE-2026-33914 - OpenEMR has SQL Injection in PostCalendar Category Delete

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the PostCalendar module contains a blind SQL injection vulnerability in the `categoriesUpdate` administrative function. The `dels` POST parameter is read via `pnVarClea…

πŸ“… Published: March 25, 2026, 11:13 p.m. πŸ”„ Last Modified: March 27, 2026, 9:29 a.m.

7.7

CVSS3.1

CVE-2026-33913 - OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted CCDA document containing `<xi:include href="file:///etc/passwd" parse="text"/>` to…

πŸ“… Published: March 25, 2026, 10:52 p.m. πŸ”„ Last Modified: March 27, 2026, 9:29 a.m.

5.4

CVSS3.1

CVE-2026-33912 - OpenEMR has reflected XSS in ajax_download.php via reportID parameter

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated attacker could craft a malicious form that, when submitted by a victim, executes arbitrary JavaScript in the victim's browser session. Version 8.0.0.3 …

πŸ“… Published: March 25, 2026, 10:51 p.m. πŸ”„ Last Modified: March 27, 2026, 9:29 a.m.

5.4

CVSS3.1

CVE-2026-33911 - OpenEMR vulnerable to reflected XSS in graphs.php via title parameter

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the POST parameter `title` is reflected back in a JSON response built with `json_encode()`. Because the response is served with a `text/html` Content-Type, the browser …

πŸ“… Published: March 25, 2026, 10:44 p.m. πŸ”„ Last Modified: March 27, 2026, 9:29 a.m.
Total resulsts: 341475
Page 104 of 34,148
Β« previous page Β» next page
Filters