Cross-site scripting in OpenEMR - CVE-2026-33912
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in the victim's browser session.
The vulnerability exists due to cross-site scripting in custom/ajax_download.php when handling the reportID POST parameter. A remote user can submit a specially crafted form to execute arbitrary JavaScript in the victim's browser session.
User interaction is required to submit the crafted form.