CVE-2026-33933

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
26/03/2026
Last modified:
26/03/2026

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to version 8.0.0.3, a reflected cross-site scripting (XSS) vulnerability in the custom template editor allows an attacker to execute arbitrary JavaScript in an authenticated staff member's browser session by sending them a crafted URL. The attacker does not need an OpenEMR account. Version 8.0.0.3 patches the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:* 7.0.2.1 (including) 8.0.0.3 (excluding)