CVE-2020-5729: Openmrs

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS. Any page that is able to trigger a UI Framework Error is susceptible to this issue.

Affected products

  • Openmrs Openmrs: up to and including 2.9.0

Published 2020-04-17. Last modified 2026-06-17.