Cross-site scripting in OpenEMR - CVE-2025-32794
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the Procedure Orders page when rendering patient names from the First and Last Name fields. A remote user can enter a crafted patient name during patient registration to execute arbitrary JavaScript in a victim's browser.
User interaction is required when another user views the affected patient's encounter under Orders > Procedure Orders.