CVE-2026-32118

MEDIUM

OpenEMR < 8.0.0.1 - Authenticated Stored Cross-Site Scripting in Graphical Pain Map Form

Title source: llm
STIX 2.1

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, stored cross-site scripting (XSS) in the Graphical Pain Map ("clickmap") form allows any authenticated clinician to inject arbitrary JavaScript that executes in the browser of every subsequent user who views the affected encounter form. Because session cookies are not marked HttpOnly, this enables full session hijacking of other users, including administrators. This vulnerability is fixed in 8.0.0.1.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0006
EPSS Percentile 18.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
open-emr/openemr < 8.0.0.1
Published Mar 11, 2026
Tracked Since Mar 12, 2026