CVE-2018-16521: Openmrs Html Form Entry

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.

Affected products

  • Openmrs Html Form Entry: version 3.7.0 only
  • Openmrs Reference Application: version 2.8.0 only

Published 2018-09-05. Last modified 2026-06-17.