Cross-site scripting vulnerability in OpenEMR prior to version 8.0.0.3
CVE-2026-33912
5.4MEDIUM
What is CVE-2026-33912?
OpenEMR, a widely used open-source electronic health records and medical practice management application, is affected by a cross-site scripting (XSS) vulnerability. An authenticated attacker could exploit this vulnerability by crafting a malicious form that, when submitted by an unsuspecting user, allows arbitrary JavaScript code execution within the victim's browser session. This could potentially compromise sensitive user data and sessions. The issue was addressed in version 8.0.0.3, where appropriate patches were implemented to protect against such attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openemr < 8.0.0.3
