Meddream
35 CVEs tracked since 2025. Since May 2025, none of them reached CISA KEV.
Meddream CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-05 | 5 | 0 |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | 30 | 0 |
Products
The products that kept showing up in Meddream's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Meddream.
- CVE-2018-25372MedDream PACS Server Premium 6.7.1.1 SQL Injection via email8.2
- CVE-2020-37009MedDream PACS Server 6.8.3.751 - Remote Code Execution8.8
- CVE-2025-54817A reflected cross-site scripting (xss) vulnerability exists in the autoPurge functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious url can lead to arbitrary javascript cod...6.1
- CVE-2025-53516A reflected cross-site scripting (xss) vulnerability exists in the downloadZip functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious url can lead to arbitrary javascript c...6.1
- CVE-2025-54495A reflected cross-site scripting (xss) vulnerability exists in the emailfailedjob functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious url can lead to arbitrary javascrip...6.1
- CVE-2025-54157A reflected cross-site scripting (xss) vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascri...6.1
- CVE-2025-54778A reflected cross-site scripting (xss) vulnerability exists in the existingUser functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript ...6.1
- CVE-2025-46270A reflected cross-site scripting (xss) vulnerability exists in the fetchPriorStudies functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javasc...6.1
- CVE-2025-55071A reflected cross-site scripting (xss) vulnerability exists in the modifyAnonymize functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascri...6.1
- CVE-2025-54852A reflected cross-site scripting (xss) vulnerability exists in the modifyAeTitle functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript...6.1
- CVE-2025-54814A reflected cross-site scripting (xss) vulnerability exists in the modifyAutopurgeFilter functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary ja...6.1
- CVE-2025-54861A reflected cross-site scripting (xss) vulnerability exists in the modifyCoercion functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascrip...6.1
- CVE-2025-57881A reflected cross-site scripting (xss) vulnerability exists in the modifyEmail functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript c...6.1
- CVE-2025-58080A reflected cross-site scripting (xss) vulnerability exists in the modifyHL7App functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript ...6.1
- CVE-2025-53854A reflected cross-site scripting (xss) vulnerability exists in the modifyHL7Route functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascrip...6.1
The record
- Peak rank
- #25 in Jan 2026
- Busiest month shown
- Jan 2026, 30 CVEs
- Months with a KEV entry
- 0 since May 2025
- Monthly snapshots
- 2 since 2025