CVE-2026-33348General(open-emr / openemr)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form are displayed on the encounter page and in the visit history for the users with the same role. Versions prior to 8.0.0.3 have a stored cross-site scripting (XSS) vulnerability in the function to display the form answers, allowing any authenticated attacker with the specific role to insert arbitrary JavaScript into the system by entering malicious payloads to the form answers. The JavaScript code is later executed by any user with the form role when viewing the form answers in the patient encounter pages or visit history. Version 8.0.0.3 contains a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openemr

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-25); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openemr

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-25: 2Mentions · 2026-03-26: 1Mentions · 2026-04-26: 1Technical Details · 2026-03-25: 1Technical Details · 2026-04-26: 103-2503-2604-26
Signal classification2 categories
General
375.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-252
Disclosure1General1
2026-03-261
General1
2026-04-261
General1
Full discourse4 posts
  • IntegSec@integ_sec
    General

    CVE-2026-33348: OpenEMR Stored XSS Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04dtkDQ0

    Post summary

    The article announces the OpenEMR stored XSS vulnerability CVE-2026-33348, outlines its business implications, and suggests general response steps, but does not provide exploit code, active exploitation evidence, or patch details.

    0000035
    30 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33348 OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role can fill Eye Exam… https://www.cve.org/CVERecord?id=CVE-2026-33348

    Post summary

    The text merely cites CVE‑2026‑33348 and links to its CVE record, providing no further technical, exploit, or mitigation detail.

    00000157
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-33348: HIGH] Beware of stored cross-site scripting (XSS) vulnerability in OpenEMR versions prior to 8.0.0.3, allowing attackers to insert malicious JavaScript in form answers.#CyberSecurity#cve,CVE-2026-33348,#cybersecurity https://cvefind.com/CVE-2026-33348

    Post summary

    The text announces a high‑severity stored XSS vulnerability (CVE‑2026‑33348) affecting OpenEMR versions before 8.0.0.3, allowing attackers to inject malicious JavaScript into form answers.

    0000035
    605 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-33348 - High OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role can fill Eye Exam forms in patient enc... https://www.thehackerwire.com/vulnerability/CVE-2026-33348/ https://t.co/ITBGqMrjvi

    Post summary

    The text mentions CVE‑2026‑33348 in OpenEMR but provides no additional details such as exploitation, patches, or technical specifics.

    0000051
    145 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopen-emropenemr---

Explore more