CVE-2026-32118
MEDIUMOpenEMR < 8.0.0.1 - Authenticated Stored Cross-Site Scripting in Graphical Pain Map Form
Title source: llmDescription
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, stored cross-site scripting (XSS) in the Graphical Pain Map ("clickmap") form allows any authenticated clinician to inject arbitrary JavaScript that executes in the browser of every subsequent user who views the affected encounter form. Because session cookies are not marked HttpOnly, this enables full session hijacking of other users, including administrators. This vulnerability is fixed in 8.0.0.1.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://github.com/openemr/openemr/security/advisories/GHSA-55qj-x8wh-m4rm
Scores
CVSS v3
5.4
EPSS
0.0006
EPSS Percentile
18.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
open-emr/openemr
< 8.0.0.1
Published
Mar 11, 2026
Tracked Since
Mar 12, 2026