CVE-2017-9380: Open-EMR Openemr

High severity, CVSS 8.8. EPSS: 15.2% chance of exploitation in the next 30 days.

OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application.

Affected products

  • Open-EMR Openemr: up to and including 5.0.0

Published 2017-06-02. Last modified 2026-06-17.