๐Ÿ” CVE Alert

CVE-2026-40508

MEDIUM 5.4

OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated attackers with Forms Administration permissions to upload template files containing arbitrary HTML or JavaScript. Attackers can inject malicious scripts through the template upload functionality, which are stored without sanitization and execute in the browser of any other Forms Administration user who views the template in the HTML editor.

CWE CWE-79
Vendor openemr
Product openemr
Published Aug 19, 2026
Last Updated Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for openemr openemr

Be the first to know when new medium vulnerabilities affecting openemr openemr are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

openemr / openemr
0 < 8.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openemr/openemr/security/advisories/GHSA-5293-8q47-cf44 github.com: https://github.com/openemr/openemr/releases/tag/v8_3_0 github.com: https://github.com/openemr/openemr/commit/ba316dd1d8de1291102da3f20f64240729ff899e vulncheck.com: https://www.vulncheck.com/advisories/openemr-stored-xss-via-patient-portal-template-import-handler

Credits

Alex Williams from Pellera Technologies VulnCheck