Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 26 March 2026

RSS

15 vulnerabilities published on 26 March 2026

Severity:
WP Job Portal Plugin Deletes Any File on WordPress Site
CVE-2026-4758
The WP Job Portal plugin for WordPress allows an attacker with a low-level account to delete any file on the site, potentially leading to serious data loss or security breaches. This issue affects all...
8.8
OpenEMR versions before 8.0.0.3 allow hackers to access sensitive data
CVE-2026-33917
OpenEMR's free electronic health records system has a security flaw that could allow an attacker with a login to access sensitive information. This issue allows hackers to access data they shouldn't h...
8.8
OpenEMR allows unauthorized access to patient notes
CVE-2026-34055
Prior to version 8.0.0.3, OpenEMR didn't properly check user permissions when updating or deleting patient notes, potentially allowing unauthorized users to access sensitive information. This has been...
8.1
OpenEMR: Unauthorized access to sensitive medical records
CVE-2026-34056
A security issue in OpenEMR allows unauthorized users to view and download sensitive medical records, potentially exposing patient information. This could lead to unauthorized data disclosure and misu...
7.7
OpenEMR: Malicious Code Can Run in Clinician's Browser
CVE-2026-33932
Before a software update, a security issue in OpenEMR allowed a hacker to inject malicious code into a patient's medical document, potentially harming the clinician's computer or stealing sensitive in...
7.6
OpenEMR: Unrestricted access to sensitive billing files
CVE-2026-33918
OpenEMR's billing file-download feature had a security weakness allowing authorized users without billing privileges to access and delete sensitive files containing patient health information. This ha...
7.6
OpenEMR PostCalendar module exposes sensitive data
CVE-2026-33914
OpenEMR's PostCalendar module in versions prior to 8.0.0.3 has a security flaw that could allow unauthorized access to sensitive information. This affects medical practices using OpenEMR. To protect y...
7.2
OpenEMR <= 8.0.0.2: Unauthorized Users Can Delete Patient Data
CVE-2026-34053
Using OpenEMR, any authorized user can delete sensitive patient data, including medical records and test results, by exploiting a previously patched bug. This can lead to lost or altered patient infor...
7.1
OpenEMR Patient Payment Data Accessible to Wrong Accounts
CVE-2026-33931
OpenEMR's patient payment portal allowed anyone with an account to see payment records for other patients, including sensitive financial and personal data, by manipulating a specific query. This has b...
6.5
SourceCodester Sales and Inventory System 1.0: Unsecured Stock Updates
CVE-2026-4826
A security issue exists in SourceCodester Sales and Inventory System 1.0, which allows unauthorized access to sensitive data when updating stock levels. This could potentially lead to data breaches or...
5.3
OpenEMR: Hackers can take over staff members' browser sessions
CVE-2026-33933
OpenEMR's custom template editor has a bug that allows a hacker to take control of a staff member's computer session by tricking them into visiting a malicious website. This could allow the hacker to ...
6.1
OpenEMR: Unrestricted Import/Export Access for Unauthorized Users
CVE-2026-34051
The free OpenEMR system for managing medical records has a security issue that allows unauthorized people to access, extract, and manipulate sensitive patient data. This happens because the system doe...
5.4
OpenEMR versions prior to 8.0.0.3 allow unauthorized access to insurance info
CVE-2026-33915
Prior to version 8.0.0.3, OpenEMR's insurance company data can be accessed or modified by users without proper permission. This is a security risk because sensitive patient information can be compromi...
5.4
OpenEMR: Patient Portal Users Can Access Staff Signatures
CVE-2026-33934
OpenEMR's patient portal in versions before 8.0.0.3 allows any patient portal user to view the signature of any medical staff member. This could be a concern for patient confidentiality and data prote...
4.3
Incorrect User ID Parsing in crun Containers
CVE-2026-30892
Crun versions 1.19-1.26 incorrectly interpret the `-u` option, allowing a process to run with higher privileges than intended. This could lead to unauthorized access to system resources. Upgrade to ve...
0.0