Cross-site scripting in OpenEMR - CVE-2026-33299
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in the Eye Exam form answer display function when rendering stored form answers on patient encounter pages or visit history. A remote user can submit a malicious form answer to execute arbitrary JavaScript in another user's browser.
User interaction is required, and the injected script executes when a user with the relevant form role views the affected encounter content or visit history.