---
id: CVE-2026-40508
title: >-
  OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in
  the patient portal template import handler that allows authenticated attackers
  with Forms Administration permissions to upload template files containing
  arbitra…
summary: >-
  OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in
  the patient portal template import handler that allows authenticated attackers
  with Forms Administration permissions to upload template files containing
  arbitra…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-08-19'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:40:01.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-40508'
references:
  - url: >-
      https://github.com/openemr/openemr/commit/ba316dd1d8de1291102da3f20f64240729ff899e
    label: disclosure@vulncheck.com
  - url: 'https://github.com/openemr/openemr/releases/tag/v8_3_0'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/openemr/openemr/security/advisories/GHSA-5293-8q47-cf44'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openemr-stored-xss-via-patient-portal-template-import-handler
    label: disclosure@vulncheck.com
  - url: 'https://github.com/openemr/openemr/security/advisories/GHSA-5293-8q47-cf44'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0021
epssPercentile: 0.1148
ingestedAt: '2026-09-09T21:22:45.539Z'
---

## Overview

OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated attackers with Forms Administration permissions to upload template files containing arbitrary HTML or JavaScript. Attackers can inject malicious scripts through the template upload functionality, which are stored without sanitization and execute in the browser of any other Forms Administration user who views the template in the HTML editor.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
