← back
CVE-2026-32127

SQL Injection Vulnerability in ajax graphs library (OpenEMR)

CVSS 8.8 HIGHEPSS 0.3%CWE-89
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 0.3%KEV nãoPoC Patch
Lifecycle
11 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, OpenEMR contains a SQL injection vulnerability in the ajax graphs library that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the ajax graphs library. This vulnerability is fixed in 8.0.0.1.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
openemr · openemr

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →