CVE-2026-33348 Details
Description
OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form are displayed on the encounter page and in the visit history for the users with the same role. Versions prior to 8.0.0.3 have a stored cross-site scripting (XSS) vulnerability in the function to display the form answers, allowing any authenticated attacker with the specific role to insert arbitrary JavaScript into the system by entering malicious payloads to the form answers. The JavaScript code is later executed by any user with the form role when viewing the form answers in the patient encounter pages or visit history. Version 8.0.0.3 contains a patch.
A stored cross-site scripting vulnerability has been identified in OpenEMR versions prior to 8.0.0.3. This issue affects users with the 'Notes - my encounters' role, who can fill out Eye Exam forms in patient encounters. The vulnerability arises in the function that displays form answers, allowing authenticated attackers with the specific role to inject arbitrary JavaScript by entering malicious payloads into the form responses. The injected JavaScript is executed by any user with the form role when viewing the encounter pages or visit history.
Users can update to OpenEMR version 8.0.0.3 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openemr/openemr/security/advisories/GHSA-6ch2-p26g-x33h | CISA-ADP | ExploitVendor Advisory |
| https://github.com/openemr/openemr/commit/f488efbe3eb7f17d0f057f960020cb611149f8a2 | [email protected] | Patch |
| https://github.com/openemr/openemr/releases/tag/v8_0_0_3 | [email protected] | Product |
| https://github.com/openemr/openemr/security/advisories/GHSA-6ch2-p26g-x33h | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| open-emr openemr | < 8.0.0.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | CVE Modified | CISA-ADP |
| Mar 25, 2026 | New CVE Received | [email protected] |