PT-2026-28152 · Openemr · Openemr

Published

2026-03-25

·

Updated

2026-03-26

·

CVE-2026-33932

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.3
Description OpenEMR is an electronic health records and medical practice management application. A stored cross-site scripting issue exists in the CCDA document preview functionality. An attacker who can upload or send a CCDA document can execute arbitrary JavaScript in a clinician’s browser session when the document is previewed. The XSL stylesheet does not sanitize the linkHtml attribute, allowing href="javascript:..." and event handler attributes to bypass sanitization. The vulnerable parameter is linkHtml.
Recommendations Update to version 8.0.0.3 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-33932
GHSA-G77X-9P3X-2J8F

Affected Products

Openemr