Cross-site scripting in OpenEMR - CVE-2026-33348
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser.
The vulnerability exists due to cross-site scripting in the Eye Exam form answer display function when rendering stored form answers for the $CHRONIC2 and $CHRONIC3 fields. A remote user can submit a crafted form payload to execute arbitrary JavaScript in a victim's browser.
User interaction is required when a user with the form role views the affected patient encounter, visit history, or print report.