PT-2026-28138 · Openemr · Openemr

Published

2026-03-25

·

Updated

2026-03-26

·

CVE-2026-33909

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.3
Description OpenEMR is an electronic health records and medical practice management application. Versions prior to 8.0.0.3 contain a flaw where variables used in the MedEx recall/reminder processing code are directly included in SQL queries without proper sanitization. This allows for potential SQL injection. The vulnerable code concatenates variables directly into SQL queries without parameterization or type casting.
Recommendations Update to version 8.0.0.3 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-33909
GHSA-6VX2-W9HW-PRQJ

Affected Products

Openemr