PatchSiren

openemr CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM openemr CVE published 2026-08-19

CVE-2026-76614

OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel POST parameter is passed to the archive restore handler without sanitization for path traversal sequences. This vulnerability allows an authenticated user with EOB Data Entry permissions to probe arbitrary filesystem paths on the server to determine file existence. OpenEMR users and admini [truncated]

MEDIUM openemr CVE published 2026-08-19

CVE-2026-40509

OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter in the DICOM viewer page is embedded unsanitized as a URL without validation against expected path formats. An attacker can craft a URL that causes an authenticated user with Patients - Documents permissions to make authenticated requests to arbitrary OpenEMR endpoints, enabling forced [truncated]

MEDIUM openemr CVE published 2026-08-19

CVE-2026-40508

CVE-2026-40508 is a stored cross-site scripting vulnerability in OpenEMR's patient portal template import handler. Authenticated attackers with Forms Administration permissions can upload template files containing arbitrary HTML or JavaScript, which are stored without sanitization and execute in the browser of other Forms Administration users who view the template in the HTML editor.

MEDIUM openemr CVE published 2026-08-19

CVE-2026-40507

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T15:17:01.530Z and has not been modified since then. CVE-2026-40507 is a reflected cross-site scripting vulnerability in OpenEMR before 8.3.0. The vulnerability exists in the patient portal template import handler, where the templateHtml GET parameter is reflected into the page response without sa [truncated]

HIGH openemr CVE published 2026-08-17

CVE-2026-40506

CVE-2026-40506 is a path traversal vulnerability in OpenEMR before version 8.2.0. The vulnerability exists in the standard_tables_manage.php interface where the db GET parameter is passed without validation to temp_dir_cleanup(). This allows attackers to supply a traversal sequence in the db parameter to resolve outside the intended temporary directory. By chaining this with an open redirect in dicom_fram [truncated]

MEDIUM openemr CVE published 2026-08-03

CVE-2026-67612

OpenEMR patient portal template system has a stored cross-site scripting vulnerability allowing authenticated administrators to inject HTML and JavaScript. The vulnerability exists due to lack of output encoding at template retrieval endpoint and missing HttpOnly cookie attributes. This enables attackers to exfiltrate session tokens via document.cookie access, leading to full session hijacking of any admi [truncated]

HIGH openemr CVE published 2026-08-03

CVE-2026-67610

CVE-2026-67610 is an improper authentication vulnerability in OpenEMR's OAuth2 dynamic client registration endpoint. This allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by providing a self-generated RSA keypair. Once approved by an administrator, attackers can obtain access tokens granting read access to all FHIR resources across all patients.

CRITICAL openemr CVE published 2026-08-03

CVE-2026-39932

OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads into the categories database table. Attackers can chain arbitrary SQL execution to alter the id column type to VARCHAR and insert a malicious PHP payloa [truncated]

HIGH openemr CVE published 2026-08-03

CVE-2026-39931

OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature. This CVE record was published on 2026-08-03T17:16:36.723Z and has not been modified since then. The vulnerability allows administrators with admin or super ACL privileges to execute arbitrary DDL and DML statements against the application database by uploading a crafted SQL file at the f [truncated]

HIGH openemr CVE published 2026-06-10

CVE-2026-46518

CVE-2026-46518 is a high-severity vulnerability in OpenEMR, a free and open-source electronic health records application. A stored cross-site scripting (XSS) vulnerability exists in the prescription CSS/HTML multi-print feature, allowing a patient portal user to execute arbitrary JavaScript in a clinician's browser session. This is possible because patient demographic fields (name, address) are rendered w [truncated]