Skip to main content
HIGH

CVE-2025-43860

OpemEMR Vulnerable to Stored XSS Attack in the Additional Address Section of Patient Demographics

CVSS v3

7.6

HIGH

EPSS Score

14.1 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.3.4 allows any authenticated user with patient creation and editing privileges to inject arbitrary JavaScript code into the system by entering malicious payloads in the (1) Text Box fields of Address, Address Line 2, Postal Code and City fields and (2) Drop Down menu options of Address Use, State and Country of the Ad

Technical details

Published
2025-05-23
Last Modified
2025-07-02

Frequently asked questions

What is CVE-2025-43860?

OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.3.4 allows any authenticated user with patient creation and editing privileges to inject arbitrary JavaScript code into the system by entering malicious payloads in the (1) Text Box fields of Address, Address Line 2, Postal Code and City fields and (2) Drop Down menu options of Address Use, State and Country of the Ad

Is CVE-2025-43860 actively exploited?

A proof-of-concept exploit exists for CVE-2025-43860, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2025-43860?

CVE-2025-43860 has a CVSS v3 base score of 7.6 (HIGH severity).

Is CVE-2025-43860 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key