Products: 10
    Vulnerabilities: 32
    Known Exploited: 0
    6
    Critical Level Threats
    6
    High Level Threats
    12
    Medium Level Threats
    8
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-41258

    OpenMRS: Stored Velocity SSTI to RCE via ConceptReferenceRange

    Last Modified: May 17, 2026
    Published: May 15, 2026

    CVE-2026-40076

    OpenMRS Core arbitrary file write and code execution via Zip Slip in module upload

    Last Modified: May 11, 2026
    Published: May 06, 2026

    CVE-2026-40075

    OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServlet

    Last Modified: May 12, 2026
    Published: May 05, 2026

    CVE-2025-25928

    A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted request. In this case, an attacker could elevate a low-privileged account to an administrative role by leveraging the CSRF vulnerability at the /admin/users/user.form endpoint.

    Last Modified: Jul 07, 2025
    Published: Mar 11, 2025

    CVE-2025-25925

    A stored cross-scripting (XSS) vulnerability in Openmrs v2.4.3 Build 0ff0ed allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the personName.middleName parameter at /openmrs/admin/patients/shortPatientForm.form.

    Last Modified: May 21, 2025
    Published: Mar 11, 2025
    Items Per Page
    Openmrs Vulnerabilities & Security CVEs | CVE-DB