CVE-2026-33933 - Vulnerability Analysis
MediumCVSS: 6.1Last Updated: March 26, 2026
OpenEMR - Reflected XSS
Published: March 26, 2026Updated: March 26, 2026PoC AvailableRemote Exploitable
Overview
OpenEMR >= 7.0.2.1 and < 8.0.0.3 contains a reflected XSS caused by improper sanitization in the custom template editor, letting unauthenticated attackers execute arbitrary JavaScript in staff browsers via crafted URLs.
Severity & Score
Severity: Medium
CVSS Score: 6.1
Impact
Attackers can execute arbitrary JavaScript in authenticated staff browsers, potentially stealing session data or performing actions on their behalf.
Mitigation
Upgrade to version 8.0.0.3 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-33933
- Severity
- Medium
- CVSS Score
- 6.1
- Type
- reflected_xss
- Status
- confirmed
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N