CVE-2025-29789: Open-EMR Openemr

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.3.0 are vulnerable to Directory Traversal in the Load Code feature. Version 7.3.0 contains a patch for the issue.

Affected products

  • Open-EMR Openemr: before 7.0.3 (fixed in 7.0.3)

Published 2025-03-25. Last modified 2026-06-17.