Cross-site scripting in OpenEMR - CVE-2025-68277

 

Cross-site scripting in OpenEMR - CVE-2025-68277

Published: April 23, 2026


Vulnerability identifier: #VU127254
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-68277
CWE-ID: CWE-79
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to conduct phishing attacks.

The vulnerability exists due to improper neutralization of untrusted input in secure messaging link handling when rendering message content containing links. A local user can send a message containing a crafted link to conduct phishing attacks.

User interaction is required to click the link, and the linked site opens within the OpenEMR or Portal interface.


Affected software

OpenEMR

How to mitigate CVE-2025-68277

Install security update from vendor's website.

OpenEMR - update to 7.0.4

External References

Related Security Bulletins