8.8

CVSS3.1

CVE-2026-25131 - OpenEMR has Broken Access Control in Procedures Configuration

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Control vulnerability exists in the OpenEMR order types management system, allowing low-privilege users (such as Receptionist) to add and modify procedure…

📅 Published: Feb. 25, 2026, 1:55 a.m. 🔄 Last Modified: April 18, 2026, 5:45 p.m.

7

CVSS4.0

CVE-2026-25127 - OpenEMR has Broken Access Control on Care Coordination Module

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the server does not properly validate user permission. Unauthorized users can view the information of authorized users. Version 8.0.0 fixes the issue.

📅 Published: Feb. 25, 2026, 1:53 a.m. 🔄 Last Modified: April 17, 2026, 3:45 p.m.

6.5

CVSS3.1

CVE-2026-25124 - OpenEMR has Broken Access Control in Report/Clients/Message List CSV Export

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the OpenEMR application is vulnerable to an access control flaw that allows low-privileged users, such as receptionists, to export the entire message list containing sens…

📅 Published: Feb. 25, 2026, 1:50 a.m. 🔄 Last Modified: April 18, 2026, 11 a.m.

6.5

CVSS3.1

CVE-2026-24896 - OpenEMR has Broken Access Control that allows unauthorized access to EDI Logs

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Control vulnerability exists in OpenEMR’s edih_main.php endpoint, which allows any authenticated user—including low-privilege roles like Receptionist—to a…

📅 Published: Feb. 25, 2026, 1:47 a.m. 🔄 Last Modified: April 17, 2026, 3:45 p.m.

10

CVSS3.1

CVE-2026-24849 - OpenEMR Arbitrary File Read Vulnerability

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument()` method in `EtherFaxActions.php` allows authenticated users to read arbitrary files from the server filesystem. Any authenticated user (regardless …

📅 Published: Feb. 25, 2026, 1:44 a.m. 🔄 Last Modified: April 17, 2026, 3:45 p.m.

6.1

CVSS3.1

CVE-2026-24847 - OpenEMR has Open Redirect in Eye Exam Form

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Eye Exam form module allows any authenticated user to be redirected to an arbitrary external URL. This can be exploited for phishing attacks against healthcare provid…

📅 Published: Feb. 25, 2026, 1:34 a.m. 🔄 Last Modified: April 17, 2026, 3:45 p.m.

8.5

CVSS4.0

CVE-2026-2914 - Privilege Elevation via Endpoint Privilege Manager Elevation Dialogs

CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs

📅 Published: Feb. 25, 2026, 1:33 a.m. 🔄 Last Modified: April 17, 2026, 3:45 p.m.

1.2

CVSS4.0

CVE-2026-21443 - OpenEMR allows inconsistent escaping of translation function output

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the `xl()` translation function returns unescaped strings. While wrapper functions exist for escaping in different contexts (`xlt()` for HTML, `xla()` for attributes, `xl…

📅 Published: Feb. 25, 2026, 1:23 a.m. 🔄 Last Modified: April 17, 2026, 3:45 p.m.

8.7

CVSS3.1

CVE-2025-69231 - OpenEMR has a Stored XSS in GAD-7 Form that Enables Session Hijacking and Privilege Escalation

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a stored cross-site scripting vulnerability in the GAD-7 anxiety assessment form allows authenticated users with clinician privileges to inject malicious JavaScript that …

📅 Published: Feb. 25, 2026, 1:18 a.m. 🔄 Last Modified: Feb. 27, 2026, 5:25 p.m.

7.2

CVSS4.0

CVE-2025-68277 - OpenEMR allows links sent via Secure Messaging to be opened in OpenEMR and Portal

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, when a link is sent via Secure Messaging, clicking the link opens the website within the OpenEMR/Portal site. This behavior could be exploited for phishing. Version 7.0.4…

📅 Published: Feb. 25, 2026, 1:13 a.m. 🔄 Last Modified: Feb. 27, 2026, 5:27 p.m.
Total resulsts: 346533
Page 1190 of 34,654
« previous page » next page
Filters