CVE-2026-33303: OpenEMR Vulnerable to Stored XSS via Unescaped portal_login_username in Credential Print View
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 are vulnerable to stored cross-site scripting (XSS) via unescaped portalloginusername in the portal credential print view. A patient portal user can set their login username to an XSS payload, which then executes in a clinic staff member's browser when they open the "Create Portal Login" page for that patient. This crosses from the patient session context into the staff/admin session context. Version 8.0.0.2 fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33303?
CVE-2026-33303 is rated as a high severity vulnerability due to its potential for allowing stored cross-site scripting attacks.
How do I fix CVE-2026-33303?
To fix CVE-2026-33303, upgrade OpenEMR to version 8.0.0.2 or later.
What software is affected by CVE-2026-33303?
CVE-2026-33303 affects OpenEMR versions prior to 8.0.0.2.
What type of vulnerability is CVE-2026-33303?
CVE-2026-33303 is a stored cross-site scripting (XSS) vulnerability.
What impact does CVE-2026-33303 have on users?
CVE-2026-33303 can allow an attacker to execute arbitrary JavaScript in the context of an authenticated user's session.