By vendor
Open-Emr vulnerabilities
Known CVEs affecting Open-Emr products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-46518HIGH 7.7
OpenEMR versions before 8.0.0.1 contain a stored cross-site scripting (XSS) flaw in the prescription multi-print feature that allows a patient portal user to inject malicious code into a clinician's browser session. By manipulating patient demographic fields through the API, an attacker can execute arbitrary JavaScript when a clinician views prescription reports, potentially compromising the clinician's session and enabling unauthorized access to patient records or system actions.