Cross-site scripting in OpenEMR - CVE-2026-32125
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in Track Anything graph titles and labels when rendering stored track or item names in Dygraph charts. A remote user can create or modify a track or item name containing malicious script to execute arbitrary script in a victim's browser.
User interaction is required because a user must view the corresponding graph.