LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-33933

CVE-2026-33933 - Vulnerability Analysis

MediumCVSS: 6.1

Last Updated: March 26, 2026

OpenEMR - Reflected XSS

Published: March 26, 2026Updated: March 26, 2026PoC AvailableRemote Exploitable

Overview

OpenEMR >= 7.0.2.1 and < 8.0.0.3 contains a reflected XSS caused by improper sanitization in the custom template editor, letting unauthenticated attackers execute arbitrary JavaScript in staff browsers via crafted URLs.

Severity & Score

Severity: Medium
CVSS Score: 6.1

Impact

Attackers can execute arbitrary JavaScript in authenticated staff browsers, potentially stealing session data or performing actions on their behalf.

Mitigation

Upgrade to version 8.0.0.3 or later.

Details

CVE ID
CVE-2026-33933
Severity
Medium
CVSS Score
6.1
Type
reflected_xss
Status
confirmed

CWE

  • CWE-79

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N