Cross-site scripting in OpenEMR - CVE-2026-25743
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in the questionnaire answer display function when rendering stored form answers on patient encounter pages or visit history. A remote privileged user can submit a crafted questionnaire answer to execute arbitrary JavaScript in another user's browser.
User interaction is required when a user with the relevant form role views the affected patient encounter page or visit history.