librehealth CVE Vulnerabilities & Metrics

Focus on librehealth vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About librehealth Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with librehealth. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total librehealth CVEs: 22
Earliest CVE date: 20 Aug 2018, 19:31 UTC
Latest CVE date: 09 Jun 2022, 00:15 UTC

Latest CVE reference: CVE-2022-31496

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical librehealth CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.57

Max CVSS: 9.0

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 2
4.0-6.9 18
7.0-8.9 0
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS librehealth CVEs

These are the five CVEs with the highest CVSS scores for librehealth, sorted by severity first and recency.

All CVEs for librehealth

CVE-2022-31496 librehealth vulnerability CVSS: 9.0 09 Jun 2022, 00:15 UTC

LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access.

CVE-2022-31497 librehealth vulnerability CVSS: 4.3 08 Jun 2022, 12:15 UTC

LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS.

CVE-2022-31495 librehealth vulnerability CVSS: 4.3 07 Jun 2022, 15:15 UTC

LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.

CVE-2022-31494 librehealth vulnerability CVSS: 4.3 06 Jun 2022, 23:15 UTC

LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS.

CVE-2022-31498 librehealth vulnerability CVSS: 4.3 06 Jun 2022, 21:15 UTC

LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS.

CVE-2022-31492 librehealth vulnerability CVSS: 4.3 06 Jun 2022, 20:15 UTC

Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username.

CVE-2022-31493 librehealth vulnerability CVSS: 4.3 06 Jun 2022, 19:15 UTC

LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS.

CVE-2022-29940 librehealth vulnerability CVSS: 3.5 05 May 2022, 12:15 UTC

In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities.

CVE-2022-29939 librehealth vulnerability CVSS: 3.5 05 May 2022, 12:15 UTC

In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities.

CVE-2022-29938 librehealth vulnerability CVSS: 6.5 05 May 2022, 12:15 UTC

In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection.

CVE-2020-23829 librehealth vulnerability CVSS: 6.5 01 Sep 2020, 17:15 UTC

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.

CVE-2020-11439 librehealth vulnerability CVSS: 9.0 15 Jul 2020, 20:15 UTC

LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application.

CVE-2020-11438 librehealth vulnerability CVSS: 6.8 15 Jul 2020, 20:15 UTC

LibreHealth EMR v2.0.0 is affected by systemic CSRF.

CVE-2020-11437 librehealth vulnerability CVSS: 4.0 15 Jul 2020, 20:15 UTC

LibreHealth EMR v2.0.0 is affected by SQL injection allowing low-privilege authenticated users to enumerate the database.

CVE-2020-11436 librehealth vulnerability CVSS: 6.0 15 Jul 2020, 20:15 UTC

LibreHealth EMR v2.0.0 is vulnerable to XSS that results in the ability to force arbitrary actions on behalf of other users including administrators.

CVE-2018-1000839 librehealth vulnerability CVSS: 6.5 20 Dec 2018, 15:29 UTC

LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.

CVE-2018-1000650 librehealth vulnerability CVSS: 6.5 20 Aug 2018, 19:31 UTC

LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be exploitable via User controlled parameters.

CVE-2018-1000649 librehealth vulnerability CVSS: 6.5 20 Aug 2018, 19:31 UTC

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled input.

CVE-2018-1000648 librehealth vulnerability CVSS: 6.5 20 Aug 2018, 19:31 UTC

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled parameters.

CVE-2018-1000647 librehealth vulnerability CVSS: 5.5 20 Aug 2018, 19:31 UTC

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled parameter.

CVE-2018-1000646 librehealth vulnerability CVSS: 6.5 20 Aug 2018, 19:31 UTC

LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.

CVE-2018-1000645 librehealth vulnerability CVSS: 4.0 20 Aug 2018, 19:31 UTC

LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of templates allows local file disclosure that can result in Disclosure of sensitive files on the server. This attack appear to be exploitable via User controlled variable in import templates function.