Openemr Vulnerabilities

Security vulnerability tracking for Open-emr Openemr

Last updated: Feb 27, 2026
Total CVEs

2

Critical

0

With Exploits

3

Last 30 Days

0

Vulnerability Timeline

2 vulnerabilities discovered over time for Openemr

Severity Distribution

Critical0
0%
High1
50%
Medium2
100%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2026-244886.5

This vulnerability allows an attacker to send any file from the server, including sensitive information like database credentials and patient documents, to a phone number they control. It can be exploited by any authenticated user of the system, as the application does not properly restrict which files can be accessed or sent.

open-emropenemr
Exploit Available
about 1 month agoFeb 27, 2026
CVE-2022-28245.4

This vulnerability allows an attacker to bypass authorization controls and gain access to restricted areas of the OpenEMR application. To exploit this, the attacker needs to manipulate a user-controlled key, which could happen if they have access to the application or its configuration.

open-emropenemr
Exploit Available
over 3 years agoAug 15, 2022

About Open-emr Openemr Security

This page provides comprehensive security vulnerability tracking for Open-emr Openemr. Our database includes all CVEs affecting this product, updated in real-time from official sources.

Each vulnerability listing includes detailed CVSS severity analysis, exploit availability status, AI-generated explanations, and direct links to official security patches and vendor advisories.

Security Recommendations

  • • Always keep Openemr updated to the latest version
  • • Subscribe to security advisories from Open-emr
  • • Monitor this page for new vulnerabilities affecting your version
  • • Prioritize patching critical and high severity issues immediately