CVE-2025-68277
OpenEMR allows links sent via Secure Messaging to be opened in OpenEMR and Portal
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, when a link is sent via Secure Messaging, clicking the link opens the website within the OpenEMR/Portal site. This behavior could be exploited for phishing. Version 7.0.4 patches the issue.
| CWE | CWE-451 |
| Vendor | openemr |
| Product | openemr |
| Published | Feb 25, 2026 |
| Last Updated | Feb 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for openemr openemr
Be the first to know when new unknown vulnerabilities affecting openemr openemr are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
openemr / openemr
< 7.0.4