StackRadar

openemr 5.2.0 Helm chart

geek-cookbookVerified publisher

Scored 14 Sept 2026

OpenEMR is the most popular open source electronic health records and medical practice management solution.

Version 5.2.0 3 years agoapp version 6.1.0 0Artifact Hub

openemr 5.2.0 deploys 1 container image: openemr/openemr. Across them, 455 findings8 critical, 22 high 2 on CISA KEV. The highest contribution is ALPINE-CVE-2023-25690 in apache2 2.4.53-r0, fixed in 2.4.56-r0. Chart.yaml declares kubeVersion >=1.16.0-0; rendered for Kubernetes 1.16.0.

Radar Score

8,392822203222

455 findings over 1 of 1 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

1 image
ImageTagVulnerabilitiesRadar Score
openemr/openemr6.1.08222032228,392

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

222 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowALPINE-CVE-2020-21594libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2023-27535curl@7.80.0-r08.0.1-r0
LowALPINE-CVE-2022-27774curl@7.80.0-r07.80.0-r1
LowALPINE-CVE-2022-2520tiff@4.3.0-r04.4.0-r3
LowALPINE-CVE-2023-27536curl@7.80.0-r08.0.1-r0
LowALPINE-CVE-2023-38546curl@7.80.0-r08.4.0-r0
LowGHSA-jw4x-v69f-hh5wphpoffice/phpspreadsheet@1.21.01.29.4
LowALPINE-CVE-2023-3316tiff@4.3.0-r04.4.0-r4
LowGHSA-7cc9-j4mv-vcjpphpoffice/phpspreadsheet@1.21.01.29.4
LowGHSA-34x7-hfp2-rc4vtar@6.1.117.5.7
LowALPINE-CVE-2020-21595libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2020-21601libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2020-21606libde265@1.0.8-r11.0.11-r0
LowGHSA-f3qr-qr4x-j273phenx/php-svg-lib@0.3.40.5.2
LowALPINE-CVE-2020-21603libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2020-21604libde265@1.0.8-r11.0.11-r0
LowGHSA-5gpr-w2p5-6m37phpoffice/phpspreadsheet@1.21.01.29.2
LowALPINE-CVE-2020-21605libde265@1.0.8-r11.0.11-r0
LowGHSA-6m9f-8vwq-97pmsmarty/smarty@v2.6.333.0.0-beta4
LowGHSA-rgw5-rvv9-x895brace-expansion@1.1.111.1.18
LowGHSA-f5x3-32g6-xq36tar@6.1.116.2.1
LowGHSA-2528-jw5q-ww88phpseclib/phpseclib@2.0.352.0.47
LowGHSA-2qqx-w9hr-q5gxangular@1.8.2no fix listed
LowGHSA-2vrf-hf26-jrp5angular@1.8.2no fix listed
LowGHSA-qwqh-hm9m-p5hrangular@1.8.2no fix listed
LowGHSA-qq5c-677p-737qsymfony/process@v5.4.35.4.46
LowALPINE-CVE-2022-43236libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43237libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43238libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43242libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43239libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43240libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43241libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43243libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43244libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43245libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43248libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43249libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43250libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43252libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43253libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-48303tar@1.34-r01.34-r1
LowALPINE-CVE-2023-32324cups@2.3.3-r52.3.3-r7
LowGHSA-qffp-2rhf-9h96tar@6.1.117.5.10
LowGHSA-f2qx-66wf-wvvxphpseclib/phpseclib@2.0.352.0.47
LowGHSA-xqr8-7jwr-rhp7certifi@2020.12.52023.7.22
LowGHSA-529h-vh3j-85hqtwig/twig@v3.3.83.27.0
LowALPINE-CVE-2023-23915curl@7.80.0-r07.80.0-r6
LowALPINE-CVE-2023-0465openssl@1.1.1n-r01.1.1t-r2
LowGHSA-23hp-3jrh-7fpwtar@6.1.117.5.19

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
5.2.0latest3 years ago6.1.08222032228,392

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/geek-cookbook/openemr.svg)](https://charts.stackradar.io/charts/geek-cookbook/openemr)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.