By vendor

Open-Emr vulnerabilities

Known CVEs affecting Open-Emr products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-46518HIGH 7.7

    OpenEMR versions before 8.0.0.1 contain a stored cross-site scripting (XSS) flaw in the prescription multi-print feature that allows a patient portal user to inject malicious code into a clinician's browser session. By manipulating patient demographic fields through the API, an attacker can execute arbitrary JavaScript when a clinician views prescription reports, potentially compromising the clinician's session and enabling unauthorized access to patient records or system actions.