Cross-site scripting in OpenEMR - CVE-2026-33346
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in a staff member's browser.
The vulnerability exists due to cross-site scripting in portal/portal_payment.php when rendering stored payment submission data. A remote user can submit a specially crafted payment value to execute arbitrary JavaScript in a staff member's browser.
User interaction is required when a staff member reviews the payment submission in the portal activity queue.