SQL Injection Vulnerability in OpenEMR by OpenEMR
CVE-2026-33909
5.9MEDIUM
What is CVE-2026-33909?
OpenEMR, an open-source electronic health records and medical practice management application, is vulnerable to SQL injection due to improperly concatenated variables in its MedEx recall/reminder processing code. This issue arises when user input is integrated directly into SQL queries without proper parameterization or type casting. Affected versions are prior to 8.0.0.3, which includes a patch to mitigate this vulnerability. Users are advised to update their installations to the latest version to secure their systems against potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openemr < 8.0.0.3
