Cross-site scripting in OpenEMR - CVE-2025-68277
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a local user to conduct phishing attacks.
The vulnerability exists due to improper neutralization of untrusted input in secure messaging link handling when rendering message content containing links. A local user can send a message containing a crafted link to conduct phishing attacks.
User interaction is required to click the link, and the linked site opens within the OpenEMR or Portal interface.