CVE-2019-3968: Open-EMR Openemr

High severity, CVSS 8.8. EPSS: 9.6% chance of exploitation in the next 30 days.

In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creating a new form.

Affected products

  • Open-EMR Openemr: up to and including 5.0.1

Published 2019-08-20. Last modified 2026-06-17.