CVE-2026-40507: Openemr
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handler. The templateHtml GET parameter is reflected into the page response without sanitization. An attacker can craft a URL that executes arbitrary JavaScript in the browser of any authenticated user with Forms Administration permissions who visits the link, enabling session hijacking.
Affected products
- Openemr Openemr: before 8.3.0 (fixed in 8.3.0)
Published 2026-08-19. Last modified 2026-09-09.