CVE-2025-69231Disclosure(open-emr / openemr)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch open-emr openemr systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a stored cross-site scripting vulnerability in the GAD-7 anxiety assessment form allows authenticated users with clinician privileges to inject malicious JavaScript that executes when other users view the form. This enables session hijacking, account takeover, and privilege escalation from clinician to administrator. Version 8.0.0 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openemr

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-02-25); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
openemr

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-25: 3Mentions · 2026-03-02: 1Patch / Workaround · 2026-02-25: 1Technical Details · 2026-02-25: 3Technical Details · 2026-03-02: 102-2503-02
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-253
Disclosure2Patch1
2026-03-021
General1
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    General

    CVE-2025-69231 (CVSS:8.7, HIGH) is Analyzed. OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio..https://nvd.nist.gov/vuln/detail/CVE-2025-69231 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post briefly references CVE-2025-69231 with its CVSS score but provides no further details or actionable information.

    0000045
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-69231 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a stored cross-site scripting vulnera… https://www.cve.org/CVERecord?id=CVE-2025-69231

    Post summary

    The text references CVE‑2025‑69231, noting it is a stored cross‑site scripting vulnerability in OpenEMR versions before 8.0.0, but provides no PoC, exploit, or patch details.

    00000179
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-69231: HIGH] Update to OpenEMR version 8.0.0 to fix a stored cross-site scripting vulnerability in the GAD-7 anxiety assessment form, preventing session hijacking and privilege escalation. #cyberse...#cve,CVE-2025-69231,#cybersecurity https://cvefind.com/CVE-2025-69231

    Post summary

    The post announces that OpenEMR version 8.0.0 includes a patch for a stored XSS vulnerability in the GAD‑7 anxiety assessment form, preventing session hijacking and privilege escalation.

    0000042
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2025-69231** pertains to a stored Cross-Site Scripting (XSS) vulnerability present in OpenEMR versions prior to 8.0.0. Specifically, the flaw resides within the GAD-7 anxiety assessment form, a feature used by clinicians to evaluate patient anxiety levels. #Cybersecurity #CVE #HighSeverity #SecurityAlert #PrivilegeEscalation #XSS https://cvetodo.com/cve/CVE-2025-69231

    Post summary

    The post announces a stored XSS vulnerability in OpenEMR’s GAD‑7 form affecting versions before 8.0.0, providing technical details but no PoC, exploit, or patch information.

    0000052
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopen-emropenemr---

Explore more