CVE-2026-33933
EUVD-2026-1604026.03.2026, 00:16
OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to version 8.0.0.3, a reflected cross-site scripting (XSS) vulnerability in the custom template editor allows an attacker to execute arbitrary JavaScript in an authenticated staff member's browser session by sending them a crafted URL. The attacker does not need an OpenEMR account. Version 8.0.0.3 patches the issue.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| open-emr | openemr | 7.0.2.1 ≤ 𝑥 < 8.0.0.3 |
𝑥
= Vulnerable software versions
References