CVE-2018-18035: Open-EMR Openemr

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.

Affected products

  • Open-EMR Openemr: before 5.0.1.6 (fixed in 5.0.1.6)

Published 2019-04-02. Last modified 2026-06-17.