
ChrisSub08/CVE-2026-25746_SqlInjectionVulnerabilityOpenEMR7.0.4
Releases0
CVE-2026-25746 - SQL Injection Vulnerability in OpenEMR <8.0.0
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 8.8 HIGH | — | ||
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 contain a SQL injection vulnerability in prescription that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the prescription listing functionality. Version 8.0.0 fixes the vulnerability. | |||