CVE-2020-5729: Openmrs
Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.
In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS. Any page that is able to trigger a UI Framework Error is susceptible to this issue.
Affected products
- Openmrs Openmrs: up to and including 2.9.0
Published 2020-04-17. Last modified 2026-06-17.