CVE-2026-67612: OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that allows authenticated administrators to inject arbitrary HTML a
OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that allows authenticated administrators to inject arbitrary HTML and JavaScript by storing malicious payloads through the template save mode, which only filters literal PHP open tags. Attackers can exploit the lack of output encoding at the template retrieval endpoint combined with missing HttpOnly cookie attributes to exfiltrate session tokens via document.cookie access, enabling full session hijacking of any admin, clinician, or portal patient who views a poisoned template.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-67612
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-67612 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for OpenEMR
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-67611: OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers wi…nvd · 2026-08-03
- highCVE-2026-67610: OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic …nvd · 2026-08-03
- criticalCVE-2026-39932: OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category …nvd · 2026-08-03
- highCVE-2026-39931: OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup conf…nvd · 2026-08-03
More from NVD Recent CVEs
- highCVE-2026-59913: Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missin…2026-08-03
- highCVE-2026-59912: Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Impro…2026-08-03
- unknownCVE-2026-38447: osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The …2026-08-03
- unknownCVE-2026-38446: A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sa…2026-08-03
- unknownCVE-2026-38444: osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header …2026-08-03