VulnSea

openemr has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was August 2026 with 5. The median CVSS is 5.4 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
5.4
Publish → KEV
—
Last 90 days
5 prev 0

Products

  • openemr 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

openemr vulnerabilities

CVEs affecting openemr, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-76614Medium· 4.3PoC
1mo ago

OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function

OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel POST parameter is passed to the archive restore handler without sanitization for path traversal sequences. The handler …

▾ Twilightopenemr · openemrEPSS 0.40%via NVD
CVE-2026-40509Medium· 4.3
1mo ago

OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer

OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter in the DICOM viewer page is embedded unsanitized as a URL without validation against expected path formats. An attac…

▾ Sunlitopenemr · openemrEPSS 0.19%via NVD
CVE-2026-40508Medium· 5.4PoC
1mo ago

OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated attackers with Forms Administration permissions to upload template files containing arbitra…

OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated attackers with Forms Administration permissions to upload template files containing arbitra…

▾ Twilightopenemr · openemrEPSS 0.30%via NVD
CVE-2026-40507Medium· 6.1PoC
1mo ago

OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handler

OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handler. The templateHtml GET parameter is reflected into the page response without sanitization. An attacker can craft a …

▾ Twilightopenemr · openemrEPSS 0.34%via NVD
CVE-2026-40506Medium· 6.5PoC
1mo ago

OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GET parameter is passed without validation to temp_dir_cleanup(), which joins the value to the PHP temporary directory …

OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GET parameter is passed without validation to temp_dir_cleanup(), which joins the value to the PHP temporary directory …

▾ Twilightopenemr · openemrEPSS 0.70%via NVD
openemr vulnerabilities (CVEs) · VulnSea