Openemr · Openemr · CVE-2026-25746
**Name of the Vulnerable Software and Affected Versions**
OpenEMR versions prior to 8.0.0
**Description**
OpenEMR is an electronic health records and medical practice management application. Insufficient input validation in the prescription listing functionality allows authenticated attackers to exploit a SQL injection. The vulnerability is present in the prescription functionality.
**Recommendations**
Update to version 8.0.0 or later.