Skip to content
Threat Feed

Vendor

OpenEMR

4 briefs RSS
high advisory

Remote Code Execution in OpenEMR Document Category Tree

OpenEMR versions 8.2.0 and earlier are vulnerable to authenticated remote code execution via SQL injection and unsafe eval() calls in the document category tree component.

OpenEMR +1 web-application-vulnerability remote-code-execution healthcare cve-2026-39931 sql-injection web-application vulnerability authentication-bypass +1
8t 1c
medium advisory

OpenEMR Stored XSS Vulnerability in CCDA Document Preview (CVE-2026-33932)

A stored cross-site scripting (XSS) vulnerability in OpenEMR's CCDA document preview (CVE-2026-33932) allows an attacker to execute arbitrary JavaScript in a clinician's browser session by uploading a malicious CCDA document.

OpenEMR xss cve-2026-33932 health-records
2r 1t
high advisory

OpenEMR PostCalendar Blind SQL Injection Vulnerability (CVE-2026-33914)

A blind SQL injection vulnerability exists in the PostCalendar module of OpenEMR versions prior to 8.0.0.3 due to improper sanitization of the `dels` POST parameter, potentially allowing attackers to execute arbitrary SQL commands.

OpenEMR sql-injection cve-2026-33914 web-application
2r 2t
medium advisory

OpenEMR Authentication Brute Force Vulnerability (CVE-2023-54347)

OpenEMR version 7.0.1 is vulnerable to an authentication brute force attack where attackers can bypass rate limiting by sending repeated login attempts, leading to potential unauthorized access.

OpenEMR 7.0.1 authentication brute-force openemr
2r 1t 1c