In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-3963.json"