CVE-2026-33299Disclosure(open-emr / openemr)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill **Eye Exam** forms in patient encounters. The answers to the form are displayed on the encounter page and in the visit history for the users with the same role. There exists a stored cross-site scripting (XSS) vulnerability in the function to display the form answers, allowing any authenticated attacker with the specific role to insert arbitrary JavaScript into the system by entering malicious payloads to the form answers. The JavaScript code is later executed by any user with the form role when viewing the form answers in the patient encounter pages or visit history. Version 8.0.0.2 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openemr

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-20); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
openemr

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-20: 1Mentions · 2026-03-23: 1Technical Details · 2026-03-20: 103-2003-23
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-231
General1
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-33299 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role… https://www.cve.org/CVERecord?id=CVE-2026-33299

    Post summary

    The text merely links to CVE-2026-33299 without providing further technical, exploit, or mitigation details.

    0000060
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33299 Stored XSS Vulnerability in OpenEMR Eye Exam Form Prior to 8.0.0.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33299

    Post summary

    The post reports a stored XSS vulnerability in the OpenEMR eye exam form (prior to version 8.0.0.2) but provides no proof‑of‑concepts, exploitation details, or patch information.

    0000037
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopen-emropenemr---

Explore more