Cross-site scripting in OpenEMR - CVE-2025-69231
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser and escalate privileges.
The vulnerability exists due to cross-site scripting in interface/forms/gad7/view.php when rendering stored GAD-7 form values into JavaScript code. A remote user can inject malicious JavaScript into form fields to execute arbitrary script in a victim's browser and escalate privileges.
User interaction is required, and the victim must click the Edit button on a compromised GAD-7 form. Only instances with the GAD-7 form enabled are vulnerable.