4.3

CVSS3.1

CVE-2026-33934 - OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff Signaturโ€ฆ

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have a missing authorization check in `portal/sign/lib/show-signature.php` that allows any authenticated patient portal user to retrieve the drawn signature image of anโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:41 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

6.1

CVSS3.1

CVE-2026-33933 - Reflected XSS via Unescaped contextName Parameter in Custom Template Editor

OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to version 8.0.0.3, a reflected cross-site scripting (XSS) vulnerability in the custom template editor allows an attacker to execute arbitrary JavaScript inโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:40 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

7.6

CVSS3.1

CVE-2026-33932 - OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-site scripting vulnerability in the CCDA document preview allows an attacker who can upload or send a CCDA document to execute arbitrary JavaScript in a โ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:37 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 2:56 p.m.

6.5

CVSS3.1

CVE-2026-33931 - OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment page allows any authenticated portal patient to access other patients' payment reโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:36 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

5.3

CVSS4.0

CVE-2026-4826 - SourceCodester Sales and Inventory System HTTP GET Parameter update_stock.php sql injection

A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /update_stock.php of the component HTTP GET Parameter Handler. This manipulation of the argument sid causes sql injection. Remote exploitation of the attack is possibโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:35 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 1:26 p.m.

7.6

CVSS3.1

CVE-2026-33918 - OpenEMR Missing Authorization on Claim File Download Endpoint

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-download endpoint `interface/billing/get_claim_file.php` only verifies that the caller has a valid session and CSRF token, but does not check any ACL pโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:35 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

8.8

CVSS3.1

CVE-2026-33917 - OpenEMR has SQL Injection in CAMOS Form

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contais a SQL injection vulnerability in the ajax_save CAMOS form that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input vโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:31 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

8.8

CVSS3.1

CVE-2026-4758 - WP Job Portal <= 2.4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom Fileโ€ฆ

The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfields::removeFileCustom' function in all versions up to, and including, 2.4.9. This makes it possible for authenticated attackers, with Subscriber-levelโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:26 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 1:26 p.m.

5.4

CVSS3.1

CVE-2026-33915 - OpenEMR Missing ACL Checks on Insurance Company API Routes

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, five insurance company REST API routes are missing the `RestConfig::request_authorization_check()` call that every other data-modifying route in the standard API uses. โ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:23 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

7.2

CVSS3.1

CVE-2026-33914 - OpenEMR has SQL Injection in PostCalendar Category Delete

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the PostCalendar module contains a blind SQL injection vulnerability in the `categoriesUpdate` administrative function. The `dels` POST parameter is read via `pnVarCleaโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:13 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.
Total resulsts: 341589
Page 115 of 34,159
ยซ previous page ยป next page
Filters