8.1

CVSS3.1

CVE-2026-34055 - OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient notes functions in `library/pnotes.inc.php` perform updates and deletes using `WHERE id = ?` without verifying that the note belongs to a patient theโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:49 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

7.1

CVSS3.1

CVE-2026-34053 - OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the AJAX deletion endpoint `interface/forms/procedure_order/handle_deletions.php` allows any authenticated user, regardless of role, to irreverโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:46 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

5.4

CVSS3.1

CVE-2026-34051 - OpenEMR has Improper ACL On Import/Export Popup

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper access control on the Import/Export functionality, allowing unauthorized users to perform import and export actions through direct request manipulationโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:45 p.m. ๐Ÿ”„ Last Modified: March 28, 2026, 1:52 a.m.

4.3

CVSS3.1

CVE-2026-33934 - OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff Signaturโ€ฆ

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have a missing authorization check in `portal/sign/lib/show-signature.php` that allows any authenticated patient portal user to retrieve the drawn signature image of anโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:41 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

6.1

CVSS3.1

CVE-2026-33933 - Reflected XSS via Unescaped contextName Parameter in Custom Template Editor

OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to version 8.0.0.3, a reflected cross-site scripting (XSS) vulnerability in the custom template editor allows an attacker to execute arbitrary JavaScript inโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:40 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

7.6

CVSS3.1

CVE-2026-33932 - OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-site scripting vulnerability in the CCDA document preview allows an attacker who can upload or send a CCDA document to execute arbitrary JavaScript in a โ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:37 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 2:56 p.m.

6.5

CVSS3.1

CVE-2026-33931 - OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment page allows any authenticated portal patient to access other patients' payment reโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:36 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

5.3

CVSS4.0

CVE-2026-4826 - SourceCodester Sales and Inventory System HTTP GET Parameter update_stock.php sql injection

A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /update_stock.php of the component HTTP GET Parameter Handler. This manipulation of the argument sid causes sql injection. Remote exploitation of the attack is possibโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:35 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 8:01 p.m.

7.6

CVSS3.1

CVE-2026-33918 - OpenEMR Missing Authorization on Claim File Download Endpoint

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-download endpoint `interface/billing/get_claim_file.php` only verifies that the caller has a valid session and CSRF token, but does not check any ACL pโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:35 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

8.8

CVSS3.1

CVE-2026-33917 - OpenEMR has SQL Injection in CAMOS Form

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contais a SQL injection vulnerability in the ajax_save CAMOS form that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input vโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:31 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.
Total resulsts: 349182
Page 871 of 34,919
ยซ previous page ยป next page
Filters