Cross-site scripting in OpenEMR - CVE-2026-33303

 

Cross-site scripting in OpenEMR - CVE-2026-33303

Published: April 23, 2026


Vulnerability identifier: #VU127328
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-33303
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in a clinic staff member's browser session.

The vulnerability exists due to cross-site scripting in the credential print view template when rendering a stored portal_login_username value into an HTML attribute without proper escaping. A remote user can set a crafted portal username and cause a staff member to open the patient's "Create Portal Login" page to execute arbitrary script in a clinic staff member's browser session.

User interaction is required, and the issue crosses from the patient portal session context into the staff or admin session context.


Affected software

OpenEMR

How to mitigate CVE-2026-33303

Install security update from vendor's website.

OpenEMR - update to 8.0.0.2

External References

Related Security Bulletins