


Perceptive Security
SOC/SIEM Consultancy

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-site scripting…
Published:
25 maart 2026 om 23:00:00
Alert date:
26 maart 2026 om 01:02:19
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
OpenEMR, a free and open source electronic health records application, contains a stored cross-site scripting vulnerability in the CCDA document preview feature prior to version 8.0.0.3. Attackers who can upload or send CCDA documents can execute arbitrary JavaScript in clinician browser sessions when documents are previewed. The vulnerability exists because the XSL stylesheet fails to sanitize linkHtml attributes, allowing href="javascript:..." and event handler attributes to pass through unchanged. This represents a significant security risk in healthcare environments where clinicians regularly preview patient documents. The issue has been patched in version 8.0.0.3.
Technical details
Mitigation steps:
Affected products:
OpenEMR
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-33932
https://github.com/openemr/openemr/commit/95e6078889b5399b12b59117f998560cd94bd47d
https://github.com/openemr/openemr/releases/tag/v8_0_0_3
https://github.com/openemr/openemr/security/advisories/GHSA-g77x-9p3x-2j8f
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
