PT-2026-26348 · Openemr · Openemr

Pavelkohout396

+1

·

Published

2026-03-19

·

Updated

2026-03-23

·

CVE-2026-33346

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.2
Description OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) issue exists in the patient portal payment flow. This allows a patient portal user to inject arbitrary JavaScript code that will be executed in the browser of a staff member reviewing the payment submission. The malicious payload is stored in portal/lib/paylib.php and rendered without proper sanitization in portal/portal payment.php.
Recommendations Update OpenEMR to version 8.0.0.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-05088
CVE-2026-33346
GHSA-QVF6-6XC6-9QV7

Affected Products

Openemr