CVE-2026-23627 | OpenEMR up to 7.x Immunization patient_id sql injection (GHSA-x3hw-rwrg-v25h)
A vulnerability identified as critical has been detected in OpenEMR up to 7.x. This affects an unknown function of the component Immunization Module. This manipulation of the argument patient_id causes sql injection.
The identification of this vulnerability is CVE-2026-23627. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.