CVE-2026-33912: OpenEMR has reflected XSS in ajax_download.php via reportID parameter
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated attacker could craft a malicious form that, when submitted by a victim, executes arbitrary JavaScript in the victim's browser session. Version 8.0.0.3 patches the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33912?
CVE-2026-33912 has a medium severity rating due to its potential for reflected XSS attacks.
How do I fix CVE-2026-33912?
To fix CVE-2026-33912, upgrade OpenEMR to version 8.0.0.3 or later.
What type of vulnerability is CVE-2026-33912?
CVE-2026-33912 is categorized as a reflected cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-33912?
Any authenticated user of OpenEMR prior to version 8.0.0.3 may be affected by CVE-2026-33912.
What is the impact of CVE-2026-33912?
The impact of CVE-2026-33912 could allow an attacker to execute malicious scripts in the context of a victim's session.