StackRadar

openemr 5.2.0 Helm chart

geek-cookbookVerified publisher

Scored 14 Sept 2026

OpenEMR is the most popular open source electronic health records and medical practice management solution.

Version 5.2.0 3 years agoapp version 6.1.0 0Artifact Hub

openemr 5.2.0 deploys 1 container image: openemr/openemr. Across them, 455 findings8 critical, 22 high 2 on CISA KEV. The highest contribution is ALPINE-CVE-2023-25690 in apache2 2.4.53-r0, fixed in 2.4.56-r0. Chart.yaml declares kubeVersion >=1.16.0-0; rendered for Kubernetes 1.16.0.

Radar Score

8,392822203222

455 findings over 1 of 1 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

1 image
ImageTagVulnerabilitiesRadar Score
openemr/openemr6.1.08222032228,392

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

455 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowALPINE-CVE-2020-21605libde265@1.0.8-r11.0.11-r0
LowGHSA-6m9f-8vwq-97pmsmarty/smarty@v2.6.333.0.0-beta4
LowGHSA-rgw5-rvv9-x895brace-expansion@1.1.111.1.18
LowGHSA-f5x3-32g6-xq36tar@6.1.116.2.1
LowGHSA-2528-jw5q-ww88phpseclib/phpseclib@2.0.352.0.47
LowGHSA-2qqx-w9hr-q5gxangular@1.8.2no fix listed
LowGHSA-2vrf-hf26-jrp5angular@1.8.2no fix listed
LowGHSA-qwqh-hm9m-p5hrangular@1.8.2no fix listed
LowGHSA-qq5c-677p-737qsymfony/process@v5.4.35.4.46
LowALPINE-CVE-2022-43236libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43237libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43238libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43242libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43239libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43240libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43241libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43243libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43244libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43245libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43248libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43249libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43250libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43252libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-43253libde265@1.0.8-r11.0.11-r0
LowALPINE-CVE-2022-48303tar@1.34-r01.34-r1
LowALPINE-CVE-2023-32324cups@2.3.3-r52.3.3-r7
LowGHSA-qffp-2rhf-9h96tar@6.1.117.5.10
LowGHSA-f2qx-66wf-wvvxphpseclib/phpseclib@2.0.352.0.47
LowGHSA-xqr8-7jwr-rhp7certifi@2020.12.52023.7.22
LowGHSA-529h-vh3j-85hqtwig/twig@v3.3.83.27.0
LowALPINE-CVE-2023-23915curl@7.80.0-r07.80.0-r6
LowALPINE-CVE-2023-0465openssl@1.1.1n-r01.1.1t-r2
LowGHSA-23hp-3jrh-7fpwtar@6.1.117.5.19
LowGHSA-4qpc-3hr4-r2p4symfony/yaml@v4.4.375.4.52
LowGHSA-9frc-8383-795msymfony/yaml@v4.4.375.4.52
LowALPINE-CVE-2022-22844tiff@4.3.0-r04.3.0-r1
LowALPINE-CVE-2022-0909tiff@4.3.0-r04.3.0-r1
LowALPINE-CVE-2022-0924tiff@4.3.0-r04.3.0-r1
LowGHSA-7x27-g8rg-x87wangular@1.8.2no fix listed
LowGHSA-7r86-cg39-jmmjminimatch@3.0.43.1.3
LowGHSA-3qx2-6f78-w2j2dompdf/dompdf@v1.1.12.0.4
LowGHSA-w9xv-qf98-ccq4phpoffice/phpspreadsheet@1.21.01.29.2
LowGHSA-qpmx-3rfj-7rhvsymfony/mime@v5.4.35.4.52
LowALPINE-CVE-2022-0907tiff@4.3.0-r04.3.0-r1
LowGHSA-8qq5-rm4j-mr97tar@6.1.117.5.3
LowGHSA-776f-qx25-q3ccxml2js@0.2.80.5.0
LowALPINE-CVE-2023-27538curl@7.80.0-r08.0.1-r0
LowALPINE-CVE-2022-0561tiff@4.3.0-r04.3.0-r1
LowALPINE-CVE-2022-0562tiff@4.3.0-r04.3.0-r1
LowALPINE-CVE-2022-0908tiff@4.3.0-r04.3.0-r1

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
5.2.0latest3 years ago6.1.08222032228,392

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/geek-cookbook/openemr.svg)](https://charts.stackradar.io/charts/geek-cookbook/openemr)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.