Vulnerabilities > Open EMR > Openemr > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-02-07 CVE-2020-36243 OS Command Injection vulnerability in Open-Emr Openemr 5.0.2.1
The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php.
network
low complexity
open-emr CWE-78
critical
9.0
2019-09-16 CVE-2019-8371 Code Injection vulnerability in Open-Emr Openemr 5.0.16
OpenEMR v5.0.1-6 allows code execution.
network
low complexity
open-emr CWE-94
critical
9.0
2019-08-20 CVE-2019-3968 OS Command Injection vulnerability in Open-Emr Openemr
In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creating a new form.
network
low complexity
open-emr CWE-78
critical
9.0
2019-08-02 CVE-2019-14529 SQL Injection vulnerability in Open-Emr Openemr
OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
network
low complexity
open-emr CWE-89
critical
9.8
2018-02-09 CVE-2018-1000019 OS Command Injection vulnerability in Open-Emr Openemr 5.0.0
OpenEMR version 5.0.0 contains a OS Command Injection vulnerability in fax_dispatch.php that can result in OS command injection by an authenticated attacker with any role.
network
low complexity
open-emr CWE-78
critical
9.0