SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-40508

MEDIUM · CVSS 5.4 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

OpenEMR versions prior to 8.3.0 are vulnerable to a stored cross-site scripting (XSS) flaw in the patient portal template import handler, allowing authenticated users with Forms Administration permissions to upload malicious HTML or JavaScript code. This vulnerability enables attackers to execute injected scripts in the browsers of other Forms Administration users when they access the affected templates. Organizations using OpenEMR should prioritize patching this vulnerability to protect against potential exploitation by insiders or compromised accounts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-40508
Severity
MEDIUM
CVSS
5.4
EPSS
0.21%
Java

Original NVD Description

OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated attackers with Forms Administration permissions to upload template files containing arbitrary HTML or JavaScript. Attackers can inject malicious scripts through the template upload functionality, which are stored without sanitization and execute in the browser of any other Forms Administration user who views the template in the HTML editor.