Cross-site scripting in OpenEMR - CVE-2026-32118
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in the browser of a user viewing a crafted encounter form.
The vulnerability exists due to cross-site scripting in the Graphical Pain Map legend rendering in library/js/clickmap.js when processing stored annotation text. A remote user can save a crafted annotation in a Graphical Pain Map form to execute arbitrary JavaScript in the browser of a user viewing a crafted encounter form.
User interaction is required when another user opens the affected encounter form or encounter report.